CVE-2026-49814: high vulnerability (CVSS 7.2)
CVE-2026-49814 affects Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7 and several LTS releases. A high-privileged attacker with remote access could exploit an OS Command Injection flaw, enabling arbitrary command execution.
Admins should prioritize patching affected systems immediately and restrict remote access to authorized personnel only. Monitor for unusual command execution patterns as a precaution.
CVE-2026-49814 is a high-severity vulnerability (CVSS 7.2) in Dell PowerProtect Data Domain. It stems from improper neutralization of special elements in OS commands, allowing attackers to execute arbitrary commands.
The vulnerability affects versions 7.7.1.0 through 8.7, and specific LTS releases from 7.13.1.0 through 8.6.1.10. Exploitation requires remote access and high privileges, increasing the risk in compromised environments.
Dell has likely issued patches or mitigation steps. Users should update to the latest secure versions and implement strict access controls to minimize exposure to this flaw.