VYPR
Medium severity6.7NVD Advisory· Published Apr 17, 2026· Updated May 8, 2026

CVE-2026-35074

CVE-2026-35074

Description

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of special elements used in an OS Command Injection vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:dell:powerprotect_dp_series_appliance:*:*:*:*:*:*:*:*
    Range: <2.7.9
  • cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*range: >=7.7.1.0,<7.13.1.70
    • cpe:2.3:o:dell:data_domain_operating_system:8.7.0.0:*:*:*:*:*:*:*
  • Range: 7.7.1.0 through 8.7.0.0, LTS2025: 8.3.1.0 through 8.3.1.20, LTS2024: 7.13.1.0 through 7.13.1.60

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.