CVE-2026-49809: SQL Injection
Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
An attacker needs remote access and low-privileged access to the affected Dell PowerProtect Cyber Recovery deployment. No user interaction is required.
What is the likely impact if exploitation succeeds?
Successful exploitation could lead to disclosure of information. The provided severity vector indicates no stated impact to integrity or availability.
Which deployments should be considered affected?
Dell PowerProtect Cyber Recovery version 20.2 and earlier should be considered affected based on the available information. The data does not state whether any particular default configuration avoids exposure.