OS Command Injection Vulnerability in Dell PowerProtect Data Domain
CVE-2026-35074
6.7MEDIUM
What is CVE-2026-35074?
The Dell PowerProtect Data Domain product range, specifically versions 7.7.1.0 through 8.7.0.0 and selected LTS releases, is susceptible to OS command injection due to improper neutralization of input. An attacker with elevated privileges and local access can exploit this flaw, potentially leading to unauthorized arbitrary command execution with root privileges, posing serious risks to system integrity and security.
Affected Version(s)
PowerProtect Data Domain 0 < 8.6.1.10, 8.7.0.1 or later
PowerProtect Data Domain 0 < 8.3.1.30 or later
PowerProtect Data Domain 0 < 7.13.1.70 or later