CVE-2026-49499: Dell Powerprotect Data Manager

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnerability in the IAM. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

Affected products

  • Dell Powerprotect Data Manager: before 20.2 (fixed in 20.2)

Published 2026-07-22. Last modified 2026-07-29.