CVE-2026-35154

dell data_domain_operating_system: unzureichende Rechteverwaltung

mediumEPSS 0.1%

Affected

  • dell/data_domain_operating_system between 7.13.1.0..7.13.1.70
  • dell/data_domain_operating_system between 8.3.0.0..8.3.1.30
  • dell/data_domain_operating_system between 8.4.0.0..8.6.1.0

Description

Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, and LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper privilege management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges to access unauthorized delete operation.

Affected operating systems

  • other

    dell / data_domain_operating_system

Metrics

6.3
Source: nvd-v3
2.1 %
Low — this CVE sits in the lower 10% of all CVEs scored today.
Show all metrics
Severity
medium
no public PoC known
0.1 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-04-20 17:16 UTC
CWE-269

Weakness classes (CWE)

  • CWE-269Class

    Improper Privilege Management

    The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

    cwe.mitre.org →

References & sources