CVE-2026-79939

Summary

Dell PowerProtect Cyber Recovery, versions Prior to 20.3, contain an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Script injection.

Affected Software

VendorProductVersion RangeStatus
DellPower Protect Cyber Recovery0 < 20.3.0.0affected
DellCyber Recovery0 < osupdate-15.4.0-19.binaffected
DellCyber Recovery0 < osupdate-15.6.1-1.binaffected

Weaknesses

  • CWE-61: CWE-61: UNIX Symbolic Link (Symlink) Following

References