CVE-2026-49814: OS Command Injection
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-49814?
The severity of CVE-2026-49814 is rated as high with a score of 7.2.
What versions of Dell PowerProtect Data Domain are affected by CVE-2026-49814?
CVE-2026-49814 affects Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7, and LTS versions 8.6.1.0 through 8.6.1.10, 8.3.1.0 through 8.3.1.30, and 7.13.1.0 through 7.13.1.70.
How do I fix CVE-2026-49814?
To fix CVE-2026-49814, apply the latest security updates provided by Dell for the affected versions.
What type of vulnerability is CVE-2026-49814?
CVE-2026-49814 is categorized as an OS Command Injection vulnerability.
What are the potential impacts of CVE-2026-49814?
The potential impacts of CVE-2026-49814 include unauthorized access and manipulation of system commands leading to data compromise.