CVE-2026-26951: Dell Data Domain Operating System
Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain a stack-based buffer overflow vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.
Affected products
- Dell Data Domain Operating System: from 7.7.1.0, before 7.13.1.70 (fixed in 7.13.1.70); from 8.3.1.0, before 8.3.1.30 (fixed in 8.3.1.30); from 8.4.0.0, before 8.6.1.0 (fixed in 8.6.1.0)
- Dell Powerprotect Dp Series Appliance: before 2.7.9 (fixed in 2.7.9)
Published 2026-04-20. Last modified 2026-06-17.