CVE-2026-74768: SSRF
Published Sep 3, 2026
·Updated
Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Server-Side Request Forgery (SSRF) vulnerability in the REST API. A high privileged remote attacker could potentially exploit this vulnerability, leading to Information disclosure.
Affected Software
1 affected component
Dell PowerProtect Data Manager<=20.2.0.0
Event History
Sep 3, 2026
CVE Published
via MITRE·08:04 AM
Data Sourced
via MITRE·08:04 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Exploitation requires a remote attacker with high privileges in Dell PowerProtect Data Manager. No user interaction is required.
2
What is the likely impact of successful exploitation?
Successful exploitation could allow server-side requests through the REST API and lead to information disclosure. The provided data does not indicate an integrity or availability impact.
3
Which versions should be considered affected?
Dell PowerProtect Data Manager versions 20.2.0.0 and below are affected.