CVE-2026-28263: Dell Data Domain Operating System
Medium severity, CVSS 4.8. EPSS: 0.2% chance of exploitation in the next 30 days.
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain a cross-site Scripting vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
Affected products
- Dell Data Domain Operating System: from 7.7.1.0, up to and including 8.5.0.0
- Dell Powerprotect Data Domain: from 7.13.1.0, up to and including 7.13.1.50; from 8.3.1.0, up to and including 8.3.1.20
Published 2026-04-17. Last modified 2026-06-17.