CVE-2026-26354 - Vulnerability Analysis
HighCVSS: 8.1Last Updated: April 22, 2026
Dell PowerProtect Data Domain - Buffer Overflow
Published: April 22, 2026Updated: April 22, 2026Remote Exploitable
Overview
Dell PowerProtect Data Domain with DD OS 7.7.1.0 through 8.6, LTS2025 8.3.1.0 through 8.3.1.10, and LTS2024 7.13.1.0 through 7.13.1.60 contain a stack-based buffer overflow in the operating system, letting unauthenticated remote attackers execute arbitrary commands.
Severity & Score
Severity: High
CVSS Score: 8.1
Impact
Unauthenticated remote attackers can execute arbitrary commands, potentially leading to full system compromise.
Mitigation
Update to the latest available version of Dell PowerProtect Data Domain DD OS.
Related Resources
Details
- CVE ID
- CVE-2026-26354
- Severity
- High
- CVSS Score
- 8.1
- Type
- buffer_overflow
- Status
- unconfirmed
CWE
- CWE-121
CVSS Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H