VDB
CVE-2026-26944
CVE-2026-26944
PUBLISHED
CVSS 8.800000190734863 HIGH
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain a missing authentication for critical function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges. Exploitation requires an authenticated user to perform a specific action.
EPSS 0.20% · 41.4th percentile
Risk Scores
CVSS 3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
0.20%
41.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dell | PowerProtect Data Domain | 0, 0, 0 |
Exploit Intelligence
Timeline
- Apr 20, 2026 CVE Published
- Apr 20, 2026 PoC Published
- Apr 20, 2026 PoC Published
- Apr 21, 2026 Security Advisory
- Apr 22, 2026 CVE Updated
- May 18, 2026 EPSS Score
- May 19, 2026 EPSS Score
- May 20, 2026 EPSS Score
- May 21, 2026 EPSS Score
- May 22, 2026 EPSS Score
- May 23, 2026 EPSS Score
- May 24, 2026 EPSS Score