CVE-2026-49813: OS Command Injection
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neutralization of special elements used in an OS command ('OS command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
If you cannot immediately patch, restrict access so that only trusted administrators can access the Data Domain system with local access (reduce likelihood of high-privileged local exploitation).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-49813?
CVE-2026-49813 has a medium severity rating of 6.7.
How do I fix CVE-2026-49813?
To address CVE-2026-49813, update your Dell PowerProtect Data Domain to the latest version as specified in the security advisory.
What type of vulnerability is CVE-2026-49813?
CVE-2026-49813 is categorized as an OS command injection vulnerability.
Which versions of Dell PowerProtect Data Domain are affected by CVE-2026-49813?
CVE-2026-49813 affects versions 7.7.1.0 through 8.7 and specific LTS release versions of 8.6.1.0 through 8.6.1.10, 8.3.1.0 through 8.3.1.30, and 7.13.1.0 through 7.13.1.70.
What are the potential impacts of CVE-2026-49813?
Exploitation of CVE-2026-49813 could lead to significant confidentiality, integrity, and availability impacts on the affected systems.