CVE-2026-49499: High severity Dell PowerProtect Data Manager vulnerability
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnerability in the IAM. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell PowerProtect Data Managerto a version that resolves this vulnerability.Fixed in 20.2.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-49499?
The severity of CVE-2026-49499 is rated high with a score of 8.8.
How do I fix CVE-2026-49499?
To fix CVE-2026-49499, you should upgrade Dell PowerProtect Data Manager to version 20.2.0.0 or later.
What type of vulnerability is CVE-2026-49499?
CVE-2026-49499 is a Generation of Incorrect Security Tokens vulnerability found in the IAM of Dell PowerProtect Data Manager.
Who is affected by CVE-2026-49499?
Users of Dell PowerProtect Data Manager versions prior to 20.2.0.0 are affected by CVE-2026-49499.
What could be the impact of exploiting CVE-2026-49499?
Exploitation of CVE-2026-49499 could lead to elevation of privileges for a low privileged attacker with remote access.