CVE-2026-68861: OS Command Injection
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell PowerProtect Oneto a version that resolves this vulnerability.Fixed in 20.1.0.0 and below
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker needs remote access to the affected Dell PowerProtect One instance and low-privileged access. No user interaction is required.
What is the potential impact of successful exploitation?
Successful exploitation could lead to remote command execution. The listed impact includes high confidentiality, integrity, and availability impact.
Which versions should be considered affected?
Dell PowerProtect One version 20.1.0.0 and earlier are affected.