CVE-2026-35074

Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, and LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of special elements used in an OS Command Injection vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:powerprotect_dp_series_appliance:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:data_domain_operating_system:8.7.0.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-17 11:16

Updated : 2026-08-04 09:16


NVD link : CVE-2026-35074

Mitre link : CVE-2026-35074

CVE.ORG link : CVE-2026-35074


JSON object : View

Products Affected

dell

  • data_domain_operating_system
  • powerprotect_dp_series_appliance
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')