CVE-2026-23774

EUVD-2026-23879
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, contain an OS command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 11%
Affected Products (NVD)
VendorProductVersion
dellpowerprotect_dp_series_appliance
𝑥
< 2.7.9
delldata_domain_operating_system
7.7.1.0 ≤
𝑥
< 7.13.1.50
delldata_domain_operating_system
7.14.0.0 ≤
𝑥
< 8.3.1.20
delldata_domain_operating_system
8.4.0.0 ≤
𝑥
< 8.6.0.0
𝑥
= Vulnerable software versions