Server-Side Request Forgery Vulnerability in Dell PowerProtect Data Manager
CVE-2026-74768
4.1MEDIUM
What is CVE-2026-74768?
Dell PowerProtect Data Manager, specifically versions up to 20.2.0.0, is affected by a Server-Side Request Forgery (SSRF) vulnerability within the REST API. This flaw could allow a remote attacker with high privileges to exploit the system, potentially resulting in unauthorized access to sensitive information. Proper security measures and updates to the latest version are recommended to mitigate this risk.
Affected Version(s)
PowerProtect Data Manager 0 < 20.3.0.0
References
CVSS V3.1
Score:
4.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dell would like to thank saltedfish for reporting this issu