VYPR
Vypr IntelligenceAI-generatedAug 26, 2026· 15 CVEs

Dell: 15 Vulnerabilities Including Critical Command Injection Flaws Disclosed Together

Dell disclosed 15 vulnerabilities across multiple product lines, including critical command injection flaws in PowerProtect and Cloud Disaster Recovery.

Key findings

  • 15 vulnerabilities disclosed across Dell PowerProtect, Cloud Disaster Recovery, iDRAC9, and Client BIOS products.
  • Critical and High severity flaws include OS Command Injection, Improper Authentication, and Buffer Overflow.
  • Affected versions range from Dell ThinOS 10 prior to 2605_10.2518 to PowerProtect Cyber Recovery prior to 20.3.
  • Vulnerabilities could lead to unauthorized access, code execution, data tampering, and denial of service.

On August 26, 2026, a significant batch of 15 vulnerabilities was disclosed across multiple Dell product lines, including PowerProtect Cyber Recovery, PowerProtect One, Cloud Disaster Recovery, iDRAC9, and Client BIOS. The vulnerabilities, disclosed between August 24 and August 26, 2026, span a range of severity levels, with several rated as High and one Critical, posing potential risks of unauthorized access, code execution, and data tampering.

Several vulnerabilities center on command injection flaws within Dell's PowerProtect suite. CVE-2026-74770 and CVE-2026-68861, both rated High, are OS Command Injection vulnerabilities in PowerProtect One, potentially allowing remote attackers to execute code. Similarly, CVE-2026-71172 (High) and CVE-2026-70419 (Critical) affect Dell Cloud Disaster Recovery, with the latter being an OS Command Injection flaw that could lead to command execution. CVE-2026-71171, also in Cloud Disaster Recovery, is another OS Command Injection vulnerability. PowerProtect Cyber Recovery is affected by CVE-2026-49809, a Medium severity SQL Injection vulnerability.

Beyond command injection, other critical flaws were identified. CVE-2026-79938, a High severity Improper Authentication vulnerability in PowerProtect Cyber Recovery, could allow remote attackers unauthorized access. In Dell iDRAC9, CVE-2026-79940 (Medium) is an Improper Access Control vulnerability. Dell ThinOS 10 is impacted by CVE-2026-61419 (High), an Improper Access Control vulnerability that could lead to unauthorized access for local attackers. Furthermore, CVE-2026-79939 (Medium) in PowerProtect Cyber Recovery involves a Symlink Following vulnerability, potentially leading to script injection for local attackers. Dell Client BIOS is affected by CVE-2026-63693 (Medium), a local "Link Following" vulnerability.

Dell PowerProtect One versions 20.1.0.0 and below are particularly affected by multiple high-severity flaws, including CVE-2026-74770, CVE-2026-68861 (OS Command Injection), and CVE-2026-68863 (Stack-based Buffer Overflow). Dell Cloud Disaster Recovery versions 20.2 and prior are impacted by CVE-2026-71172 (SSRF), CVE-2026-71171, and CVE-2026-70419 (OS Command Injection). Dell PowerProtect Cyber Recovery versions prior to 20.3 are affected by CVE-2026-79939 (Symlink Following) and CVE-2026-79938 (Improper Authentication).

The disclosures highlight a broad range of vulnerabilities across Dell's enterprise and client offerings. Users of affected Dell products are strongly advised to consult Dell's official advisories for specific version information and recommended patches. Prompt application of updates is crucial to mitigate the risks associated with these vulnerabilities, particularly those rated High and Critical, which could lead to severe system compromise. The wide variety of affected products and vulnerability types underscores the importance of a comprehensive security strategy for Dell customers.

AI-written article. Grounded in 15 CVE records listed below.