A critical batch of vulnerabilities in its PowerProtect Data Domain product line, including two flaws with the maximum-severity CVSS score of 9.8, allows completely unauthenticated attackers to seize full control of affected systems.
The advisory, tracked as DSA-2026-218 and related bulletins, spans over 20 proprietary code vulnerabilities alongside dozens of third-party component issues affecting widely used backup and storage appliances.
Dell PowerProtect Data Domain Flaws
Two vulnerabilities stand out as the most dangerous in this disclosure. CVE-2026-53483 is an improper authentication vulnerability that lets a remote, unauthenticated attacker bypass login controls entirely and gain unauthorized access.
CVE-2026-53481 is a path traversal vulnerability that similarly requires no credentials, allowing attackers to escape restricted directories and reach sensitive system files.
Both carry a CVSS score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), meaning exploitation requires no privileges, no user interaction, and results in complete compromise of confidentiality, integrity, and availability.
Given that Data Domain appliances typically sit at the core of enterprise backup and disaster-recovery infrastructure, successful exploitation could let attackers not just breach a single system but potentially tamper with or destroy backup data a scenario ransomware operators actively seek out to eliminate recovery options before deploying encryption payloads.
Additional High-Severity Issues
Beyond the two flagship flaws, the advisory lists several other notable vulnerabilities:
- CVE-2026-56086 (CVSS 8.8): incorrect authorization exploitable by a low-privileged remote attacker for unauthorized access.
- CVE-2026-53482 (CVSS 7.5): integer overflow causing denial of service, unauthenticated and remote.
- CVE-2026-53479 and CVE-2026-53478 (CVSS 7.2 each): OS command injection flaws letting high-privileged attackers execute arbitrary commands with root-level impact.
- CVE-2026-41122 (CVSS 7.1): stored cross-site scripting that can lead to session theft or information disclosure.
The proprietary code list also includes numerous lower-severity path traversal, link-following, and information disclosure bugs that affect local or high-privilege attack paths.
Dell’s advisory also bundles patches for a long list of third-party components embedded in DD OS, including Apache Tomcat, Apache HTTP Server, Log4j, OpenSSL, Golang, GNU Binutils, PostgreSQL, Python, curl, and glibc, collectively addressing dozens of CVEs ranging from 2022 through newly disclosed issues in 2026.
This reflects the common supply chain challenge in which a single appliance inherits risk from its entire open-source dependency stack.
Affected Versions
The flaws affect DD OS versions 7.7.1.0 through 8.7, as well as the LTS2024 (7.13.1.x), LTS2025 (8.3.1.x), and LTS2026 (8.6.1.x) release branches.
Dell has published fixed versions for each track DD OS 8.7/8.8, 8.3.1.40, 8.6.1.20, and 7.13.1.80 available through the Dell Data Domain download portal.
Notably, DD3300 and DDVE platforms do not yet have the 8.3.1.40 or 8.6.1.20 builds available; Dell Engineering is still finalizing fixes for these platforms, with interim guidance published in KB 000486874.
Mitigation
Security teams running Data Domain infrastructure should treat this as an urgent patching priority given the unauthenticated, remote nature of the two critical flaws. Organizations should:
- Upgrade to the remediated DD OS version matching their release track immediately.
- Restrict management interface exposure to trusted networks where patching isn’t immediately possible.
- Monitor Dell’s KB 000486874 for DD3300/DDVE fix availability.
- Review false-positive guidance KBs after upgrading, since some scanners may still flag remediated systems.
Give your SOC the intelligence it needs to act with confidence.
Explore ANY.RUN Threat Intelligence Feeds to reduce noise and improve operational efficiency.