Weak Credentials Flaw in Dell PowerProtect Data Domain
CVE-2026-23853

8.4HIGH

Key Information:

Vendor

Dell

Vendor
CVE Published:
17 April 2026

What is CVE-2026-23853?

Dell PowerProtect Data Domain systems running specific versions of the Data Domain Operating System exhibit a vulnerability stemming from the use of weak credentials. This issue allows an unauthenticated attacker with local access to potentially exploit the flaw and gain unauthorized access to the system, posing significant risks to data integrity and security.

Affected Version(s)

PowerProtect Data Domain 0 < 8.6.0.0 or later

PowerProtect Data Domain 0 < 8.3.1.20 or later

PowerProtect Data Domain 0 < 7.13.1.50 or later

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.