CVE-2026-74770: OS Command Injection
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell PowerProtect Oneto a version that resolves this vulnerability.Fixed in 20.1.0.0 and below
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote attacker with low-privileged access to Dell PowerProtect One could potentially exploit it. No user interaction is required.
What is the potential impact?
Successful exploitation could lead to code execution with high impact to confidentiality, integrity, and availability.
Which versions should be considered affected?
Dell PowerProtect One version 20.1.0.0 and earlier are identified as affected.