improper neutralization of special elements used in an OS Command Injection vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with
root privileges.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 05 Aug 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local Privileged OS Command Injection in Dell PowerProtect Data Domain |
Tue, 04 Aug 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of special elements used in an OS Command Injection vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges. | Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, and LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of special elements used in an OS Command Injection vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges. |
Fri, 08 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dell data Domain Operating System
Dell powerprotect Dp Series Appliance |
|
| CPEs | cpe:2.3:a:dell:powerprotect_dp_series_appliance:*:*:*:*:*:*:*:* cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:* cpe:2.3:o:dell:data_domain_operating_system:8.7.0.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Dell data Domain Operating System
Dell powerprotect Dp Series Appliance |
Sat, 18 Apr 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 17 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dell
Dell powerprotect Data Domain |
|
| Vendors & Products |
Dell
Dell powerprotect Data Domain |
Fri, 17 Apr 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of special elements used in an OS Command Injection vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges. | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2026-08-04T08:05:53.780Z
Reserved: 2026-04-01T05:04:41.955Z
Link: CVE-2026-35074
Updated: 2026-04-18T02:56:15.329Z
Status : Modified
Published: 2026-04-17T11:16:10.737
Modified: 2026-08-04T09:16:36.670
Link: CVE-2026-35074
No data.
OpenCVE Enrichment
Updated: 2026-08-05T03:45:03Z