LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-23853

CVE-2026-23853 - Vulnerability Analysis

HighCVSS: 8.4

Last Updated: April 17, 2026

Dell PowerProtect Data Domain - Authentication Bypass

Published: April 17, 2026Updated: April 17, 2026

Overview

Dell PowerProtect Data Domain with DD OS 7.7.1.0 through 8.5, LTS2025 8.3.1.0 through 8.3.1.20, LTS2024 7.13.1.0 through 7.13.1.50 contains a broken authentication caused by use of weak credentials, letting unauthenticated local attackers gain unauthorized system access, exploit requires local access.

Severity & Score

Severity: High
CVSS Score: 8.4

Impact

Unauthenticated local attackers can gain unauthorized access to the system, potentially compromising system integrity and data.

Mitigation

Update to the latest available version of DD OS.

Details

CVE ID
CVE-2026-23853
Severity
High
CVSS Score
8.4
Type
broken_authentication
Status
new

CWE

  • CWE-1391

CVSS Metrics

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H