CVE-2026-26942

Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:powerprotect_dp_series_appliance:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-20 17:16

Updated : 2026-06-17 10:26


NVD link : CVE-2026-26942

Mitre link : CVE-2026-26942

CVE.ORG link : CVE-2026-26942


JSON object : View

Products Affected

dell

  • data_domain_operating_system
  • powerprotect_dp_series_appliance
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')