CVE-2026-53478: OS Command Injection
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neutralization of special elements used in an OS command ('OS command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to command execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53478?
The severity of CVE-2026-53478 is rated high with a score of 7.2.
How do I fix CVE-2026-53478?
To fix CVE-2026-53478, update your Dell PowerProtect Data Domain software to the latest version recommended by Dell.
What systems are affected by CVE-2026-53478?
CVE-2026-53478 affects Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7 and various LTS versions.
What kind of vulnerability is CVE-2026-53478?
CVE-2026-53478 is classified as an OS command injection vulnerability.
What are the potential impacts of CVE-2026-53478?
Exploiting CVE-2026-53478 may allow an attacker to execute arbitrary OS commands, leading to unauthorized access and compromise of the system.