Sensitive Information Exposure in Dell PowerProtect Data Domain Appliances
CVE-2026-23775

7.6HIGH

Key Information:

Vendor

Dell

Vendor
CVE Published:
17 April 2026

What is CVE-2026-23775?

Dell PowerProtect Data Domain appliances running the Data Domain Operating System (DD OS) versions 8.0 to 8.5, along with LTS2025 versions 8.3.1.0 to 8.3.1.10, are impacted by a vulnerability that allows sensitive information to be inadvertently logged. This risk poses a threat when a low privileged attacker gains remote access to the system, potentially exposing credentials if the authentication attempt is authorized by a high privileged user. This issue is particularly relevant for systems with retention lock enabled.

Affected Version(s)

PowerProtect Data Domain appliances 0 < 8.6.0.0 or later

PowerProtect Data Domain appliances 0 < 8.3.1.20 or later

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.