CVE-2026-53479: OS Command Injection
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neutralization of special elements used in an OS command ('OS command Injection') vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to protection mechanism bypass. This is a Critical vulnerability as it allows an attacker to invoke arbitrary command execution with root privileges; so Dell recommends customers to upgrade at the earliest opportunity.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell PowerProtect Data Domainto a version that resolves this vulnerability.Fixed in 8.6.1.10 - Upgrade
Upgrade
Dell PowerProtect Data Domainto a version that resolves this vulnerability.Fixed in 8.3.1.30 - Upgrade
Upgrade
Dell PowerProtect Data Domainto a version that resolves this vulnerability.Fixed in 7.13.1.70
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53479?
CVE-2026-53479 has a high severity rating of 7.2.
How do I fix CVE-2026-53479?
To fix CVE-2026-53479, update your Dell PowerProtect Data Domain to the latest patched version as recommended by Dell.
What type of vulnerability is CVE-2026-53479?
CVE-2026-53479 is classified as an OS Command Injection vulnerability.
Which versions of Dell PowerProtect Data Domain are affected by CVE-2026-53479?
CVE-2026-53479 affects Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7 and various LTS release versions.
What impact does CVE-2026-53479 have on affected systems?
CVE-2026-53479 can lead to high impacts including potential unauthorized command execution on affected systems.