CVE-2026-22266: Dell Powerprotect Data Manager

High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Improper Verification of Source of a Communication Channel vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.

Affected products

  • Dell Powerprotect Data Manager: before 19.22 (fixed in 19.22)

Published 2026-02-19. Last modified 2026-06-17.