CVE-2026-35154
6.3
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
Summary
Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, and LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper privilege management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges to access unauthorized delete operation.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Dell | PowerProtect Data Domain appliances | 0 < 8.7.0.1 or later | affected |
| Dell | PowerProtect Data Domain appliances | 0 < 8.3.1.30 or later | affected |
| Dell | PowerProtect Data Domain appliances | 0 < 7.13.1.70 or later | affected |
Weaknesses
- CWE-269: CWE-269: Improper Privilege Management
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.