CVE-2026-49809: Dell Powerprotect Cyber Recovery

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.

Affected products

  • Dell Powerprotect Cyber Recovery: before 20.3.0.0 (fixed in 20.3.0.0)

Published 2026-08-26. Last modified 2026-09-02.