FILTERING BY: CLEAR FILTER

Dell PowerProtect Data Domain Privilege Escalation CVE-2026-41124

CVE-2026-41124 is a critical path traversal vulnerability (CWE-22) affecting the Dell PowerProtect Data Domain management interface and API. Attackers can utilize directory traversal sequences (e.g., ../) to bypass restricted directory boundaries, granting unauthorized access to sensitive system files, credential stores, and configuration binaries. This flaw allows an attacker to escalate privileges from a low-privileged or unauthenticated state to administrative or root-level control. Because Data Domain appliances are central to enterprise backup and disaster recovery, this vulnerability poses a severe risk to data availability, potentially enabling threat actors to destroy backup repositories to ensure ransomware success. Remediation is available via Dell Security Advisory DSA-2026-278.

Links:VulDB, Cve, Radar, Dell, Tenable, Strix, Nvd, Github

LINK COPIED TO CLIPBOARD