CVE-2026-46738: Input Validation
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell PowerProtect Data Managerto a version that resolves this vulnerability.Fixed in 20.2.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46738?
The severity of CVE-2026-46738 is classified as critical with a CVSS score of 9.1.
How do I fix CVE-2026-46738?
To fix CVE-2026-46738, upgrade the Dell PowerProtect Data Manager to version 20.2.0.0 or later.
What type of vulnerability is identified in CVE-2026-46738?
CVE-2026-46738 identifies an Improper Input Validation vulnerability in the REST API.
What could an attacker achieve by exploiting CVE-2026-46738?
An attacker could potentially exploit CVE-2026-46738 to gain elevated privileges remotely.
Which versions of Dell PowerProtect Data Manager are affected by CVE-2026-46738?
Versions of Dell PowerProtect Data Manager prior to 20.2.0.0 are affected by CVE-2026-46738.