CVE-2026-22267Disclosure(dell / powerprotect_data_manager)

LOWCVSS 8.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch dell powerprotect_data_manager systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-266

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • powerprotect_data_manager

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
powerprotect_data_manager

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-19: 3Patch / Workaround · 2026-02-19: 1Technical Details · 2026-02-19: 302-19
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-22267 - High Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with remote access could potentially exploit t... https://www.thehackerwire.com/vulnerability/CVE-2026-22267/ https://t.co/scTcmxXic1

    Post summary

    The post discloses CVE‑2026‑22267, a high‑severity incorrect privilege assignment flaw in Dell PowerProtect Data Manager versions before 19.22, which could allow a low‑privileged remote attacker to gain elevated access.

    0000031
    112 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-22267** pertains to Dell PowerProtect Data Manager versions prior to 19.22. It is classified as an **Incorrect Privilege Assignment** vulnerability, which allows a low-privileged attacker with remote access to potentially escalate their privileges within the system. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #PrivilegeEscalation #AuthBypass https://cvetodo.com/cve/CVE-2026-22267

    Post summary

    The post announces CVE‑2026‑22267, a privilege‑escalation vulnerability in Dell PowerProtect Data Manager.

    0000031
    20 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 HIGH severity alert: Dell PowerProtect Data Manager (pre-19.22) is vulnerable to privilege escalation (CVE-2026-22267). Restrict remote access & monitor for unusual activity! 🔒 https://radar.offseq.com/threat/cve-2026-22267-cwe-266-incorrect-privilege-assignm-254d0ded #OffSe... https://t.co/eHxiLuPGcb

    Post summary

    Dell PowerProtect Data Manager (pre‑19.22) has a high‑severity privilege escalation flaw (CVE‑2026‑22267); recommended mitigations include restricting remote access and monitoring activity, though no exploit or patch link is provided.

    0000034
    265 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdellpowerprotect_data_manager---

Explore more