CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-53481

CVSS 9.8v3.1pub. 2026-07-07upd. 2026-07-08

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to the system. This is a critical severity vulnerability as it allows an attacker to take complete control of system; so Dell recommends customers to upgrade at the earliest opportunity.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Dell Data Domain Operating System

    OS
    Dell
    7.7.1.0 – 7.13.1.80 (excl.)7.14.0.0 – 8.3.1.40 (excl.)8.4.0.0 – 8.6.1.20 (excl.)8.7.0.0 – 8.8.0.0 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Path TraversalAuth Bypass
CWE
References

Related vulnerabilities

CVE-2026-53483CRITICAL9.8PL ✓same product

Obejście uwierzytelniania w Dell PowerProtect Data Domain (Auth Bypass)

CVE-2025-36594CRITICAL9.8PL ✓same product

Authentication Bypass by Spoofing w Dell PowerProtect Data Domain DD OS

CVE-2026-53482HIGH7.5PL ✓same product

Integer overflow w Dell PowerProtect Data Domain — podatność DoS

CVE-2026-41122HIGH7.1PL ✓same product

Stored XSS w Dell PowerProtect Data Domain — kradzież sesji

CVE-2026-56086HIGH8.8PL ✓same product

Nieprawidłowa autoryzacja w Dell PowerProtect Data Domain