CVE-2026-35154
Modified
Modified - Updated After Analysis
Improper Privilege Management in Dell PowerProtect IDRAC Enables Privilege Escalation
Publication date: 2026-04-20
Last updated on: 2026-05-11
Assigner: Dell
Description
Description
Dell PowerProtect Data Domain appliances, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper privilege management vulnerability.
A high privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges to access unauthorized delete operation.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| dell | data_domain_operating_system | From 7.13.1.0 (inc) to 7.13.1.70 (exc) |
| dell | data_domain_operating_system | From 8.3.0.0 (inc) to 8.3.1.30 (exc) |
| dell | data_domain_operating_system | From 8.4.0.0 (inc) to 8.6.1.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-269 | The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor. |