Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-53481: Dell PowerProtect Data Domain, Path Traversal Risk, Unauthorized Access

CVE-2026-53481 CVE-2026-53481
Summary

Dell PowerProtect Data Domain, a data management system, contains a vulnerability that allows an unauthorized attacker to gain full access to the system. This could lead to sensitive data being compromised and the attacker taking control of the system. To protect against this, Dell recommends upgrading to the latest version of the software as soon as possible.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
dell powerprotect data domain < 8.8.0.0 or later
Original title
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 th...
Original description
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to the system. This is a critical severity vulnerability as it allows an attacker to take complete control of system; so Dell recommends customers to upgrade at the earliest opportunity.
mitre CVSS3.1 9.8
Vulnerability type
CWE-22 Path Traversal
Published: 7 Jul 2026 · Updated: 23 Jul 2026 · First seen: 7 Jul 2026