CVE-2026-71171: OS Command Injection
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Exploitation requires a high-privileged attacker with remote access to the Dell Cloud Disaster Recovery REST API. The supplied information does not indicate that unauthenticated or low-privileged users can exploit it.
Which deployments are affected?
Dell Cloud Disaster Recovery versions 20.2 and prior are identified as affected. The available information does not state whether the vulnerable REST API is enabled or exposed in a default configuration.
What is the potential impact of successful exploitation?
A successful attacker could execute OS commands remotely through the REST API. The reported impact includes high confidentiality, integrity, and availability impact.