Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of argument delimiters in a command ('argument injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 17 Apr 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Argument Injection Vulnerability in Dell PowerProtect Data Domain Allows Local Privileged Command Execution |
Fri, 17 Apr 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of argument delimiters in a command ('argument injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges. | |
| Weaknesses | CWE-88 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2026-04-17T10:38:18.357Z
Reserved: 2026-04-01T17:04:27.475Z
Link: CVE-2026-35153
No data.
Status : Received
Published: 2026-04-17T11:16:10.870
Modified: 2026-04-17T11:16:10.870
Link: CVE-2026-35153
No data.
OpenCVE Enrichment
Updated: 2026-04-17T11:30:16Z
Weaknesses