CVE-2026-41122
Analyzed Analyzed - Analysis Complete

Stored XSS in Dell PowerProtect Data Domain

Vulnerability report for CVE-2026-41122, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-08

Last updated on: 2026-07-08

Assigner: Dell

Description

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain a stored cross-site scripting vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability. Exploitation may lead to information disclosure, session theft, or client-side request forgery.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-08
Last Modified
2026-07-08
Generated
2026-07-12
AI Q&A
2026-07-08
EPSS Evaluated
2026-07-11
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
dell data_domain_operating_system From 7.7.1.0 (inc) to 7.13.1.80 (exc)
dell data_domain_operating_system From 8.7.0.0 (inc) to 8.8.0.0 (exc)
dell data_domain_operating_system From 7.14.0.0 (inc) to 8.3.1.40 (exc)
dell data_domain_operating_system From 8.4.0.0 (inc) to 8.6.1.20 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a stored cross-site scripting (XSS) issue found in Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7, including specific LTS releases. It allows an unauthenticated attacker with remote access to inject malicious scripts that are stored and later executed in the context of a user's browser.

Exploitation of this vulnerability could lead to unauthorized actions such as information disclosure, session theft, or client-side request forgery.

Impact Analysis

If exploited, this vulnerability can impact you by allowing attackers to steal sensitive information, hijack user sessions, or perform unauthorized actions on behalf of the user through client-side request forgery.

Such impacts can compromise the confidentiality, integrity, and availability of your data and systems.

Compliance Impact

The vulnerability in Dell PowerProtect Data Domain could lead to information disclosure, session theft, or client-side request forgery. Such security issues may impact the confidentiality and integrity of sensitive data.

Because of potential information disclosure and session theft, this vulnerability could negatively affect compliance with data protection standards and regulations such as GDPR and HIPAA, which require safeguarding personal and sensitive information against unauthorized access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-41122. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart