OS Command Injection Vulnerability in Dell Cloud Disaster Recovery
CVE-2026-70419
9.1CRITICAL
What is CVE-2026-70419?
Dell Cloud Disaster Recovery, up to version 20.2, has a vulnerability categorized as OS Command Injection. This flaw allows an authenticated attacker with high privileges to exploit it remotely, potentially leading to unauthorized command execution on the server. Effectively mitigating this vulnerability is crucial to ensure the security and integrity of affected systems.
Affected Version(s)
Cloud Disaster Recovery 0
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dell would like to thank Ahmed Y. Elmogy for reporting this issue: CVE-2026-70419