CVE-2026-49809

Summary

Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.

Affected Software

VendorProductVersion RangeStatus
DellPower Protect Cyber Recovery0 < 20.3.0.0affected
DellCyber Recovery0 < osupdate-15.4.0-19.binaffected
DellCyber Recovery0 < osupdate-15.6.1-1.binaffected

Weaknesses

  • CWE-89: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

References