CVE-2026-35153

Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, and LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of argument delimiters in a command ('argument injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:powerprotect_dp_series_appliance:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:data_domain_operating_system:8.7.0.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-17 11:16

Updated : 2026-08-04 09:16


NVD link : CVE-2026-35153

Mitre link : CVE-2026-35153

CVE.ORG link : CVE-2026-35153


JSON object : View

Products Affected

dell

  • data_domain_operating_system
  • powerprotect_dp_series_appliance
CWE
CWE-88

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')