CVE-2026-49815: OS Command Injection
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neutralization of special Elements used in an OS command ('OS command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to execution of arbitrary OS commands.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-49815?
The severity of CVE-2026-49815 is rated as high, with a score of 7.2.
What versions are affected by CVE-2026-49815?
CVE-2026-49815 affects Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7 and various LTS releases.
How do I fix CVE-2026-49815?
To mitigate CVE-2026-49815, users should apply the recommended security update provided by Dell.
What type of vulnerability is CVE-2026-49815?
CVE-2026-49815 is classified as an OS Command Injection vulnerability.
What impact does CVE-2026-49815 have on affected systems?
CVE-2026-49815 can result in confidentiality breaches, integrity issues, and denial of service on affected systems.