Stack-based Buffer Overflow in Dell PowerProtect Data Domain
CVE-2026-26354

8.1HIGH

Key Information:

Vendor

Dell

Vendor
CVE Published:
22 April 2026

What is CVE-2026-26354?

The vulnerability presents a stack-based buffer overflow in Dell's PowerProtect Data Domain, affecting multiple versions of its Domain Operating System. An unauthenticated remote attacker could exploit this flaw to execute arbitrary commands on the system, posing serious security risks to the data integrity and availability of affected environments.

Affected Version(s)

PowerProtect Data Domain 0 < 8.6.1.10, 8.7.0.0 or later

PowerProtect Data Domain 0 < 8.3.1.20 or later

PowerProtect Data Domain 0 < 7.13.1.60 or later

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.