CVE-2026-74769: Medium severity Dell PowerProtect Data Manager vulnerability
Published Sep 3, 2026
·Updated
Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain an Incorrect Authorization vulnerability in the REST API. A low privileged remote attacker could potentially exploit this vulnerability, leading to Protection mechanism bypass.
Affected Software
1 affected component
Dell PowerProtect Data Manager<=20.2.0.0
Event History
Sep 3, 2026
CVE Published
via MITRE·08:10 AM
Data Sourced
via MITRE·08:10 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker must be remote and authenticated with a low-privileged account. No user interaction is required.
2
Which deployments should be considered affected?
Dell PowerProtect Data Manager versions 20.2.0.0 and below are identified as affected. The provided information does not state whether any particular configuration or default deployment changes exposure.
3
What is the likely impact if exploitation succeeds?
Successful exploitation could allow bypass of protection mechanisms. The reported impact is integrity-focused; no confidentiality or availability impact is specified.