CVE-2026-53481Disclosure(dell / data_domain_operating_system)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch dell data_domain_operating_system systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to the system. This is a critical severity vulnerability as it allows an attacker to take complete control of system; so Dell recommends customers to upgrade at the earliest opportunity.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • data_domain_operating_system

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-07-15); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
data_domain_operating_system

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-07-08: 1Mentions · 2026-07-15: 2Mentions · 2026-07-23: 1Patch / Workaround · 2026-07-15: 1Patch / Workaround · 2026-07-23: 1Technical Details · 2026-07-08: 1Technical Details · 2026-07-15: 2Technical Details · 2026-07-23: 107-0807-1507-23
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-07-081
Disclosure1
2026-07-152
Disclosure1Patch1
2026-07-231
Patch1
Full discourse4 posts
  • connect24h@connect24h
    Disclosure

    バックアップ基盤は最後の砦ではなく、侵害時の急所だ。Dell PowerProtect Data Domainで143件、うち製品固有26件の脆弱性。CVE-2026-53481/53483はCVSS 9.8、認証なしremote accessでsystem controlの可能性がある。 現場では「本番系より後で」は通用しない。DD OS 7.7.1.0〜8.7、LTS2024/2025/2026系の枝番、管理IFの到達元ACL、保守VPN、復元手順の代替可否を今日棚卸ししてほしい。バックアップ装置を取られると、復旧計画そのものが崩れる。#セキュリティ

    Post summary

    Dell PowerProtect Data Domain is exposed to critical vulnerabilities (CVE-2026-53481/53483) with unauthenticated remote access potentially leading to system control; immediate action is required to assess and secure affected installations.

    10001304
    4.3K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Dell PowerProtect Data Domain の複数の脆弱性が FIX:リモートからのシステム侵害の恐れ https://iototsecnews.jp/2026/07/15/multiple-dell-powerprotect-vulnerabilities-allow-hackers-to-gain-full-system-access-remotely/ 今回の脆弱性は、製品における不適切な認証やパス名の制限不備といった、システム設計時や実装時の検証漏れが主な原因となっています。特に CVE-2026-53483 や CVE-2026-53481 は、不適切な認証や制御に起因し、外部からのシステム制御の奪取に至る恐れがあります。ご利用のチームは、アップグレードをお急ぎください。 #CVE202653481 #CVE202653483 #Dell #PowerProtectDataDomain #Vulnerability

    Post summary

    The article warns that Dell PowerProtect Data Domain suffers from CVE-2026-53483 and CVE-2026-53481, which allow remote system takeover via improper authentication, and it urges users to upgrade as the primary mitigation.

    01000115
    501 followersView on X
  • TECHEPAGES@techepages
    Patch

    🚨 Critical: Dell PowerProtect Data Domain backup appliances hit by 20+ flaws, incl. two unauthenticated CVSS 9.8 bugs enabling full remote takeover (DSA-2026-218) • CVE-2026-53483: login bypass • CVE-2026-53481: path traversal • Backups = ransomware's first target Patch now: • Upgrade: 8.7/8.8, 8.3.1.40, 8.6.1.20 or 7.13.1.80 • Restrict mgmt interfaces • DD3300/DDVE: watch KB 000486874

    Post summary

    Dell PowerProtect Data Domain appliances are vulnerable to multiple critical CVEs, including a login bypass and a path traversal that allow remote takeover; patches and interface restrictions are recommended.

    0000048
    23 followersView on X
  • キタきつね@foxbook
    Disclosure

    CVE-2026-53481およびCVE-2026-53483:Dell PowerProtectの完全乗っ取り(9.8) CVE-2026-53481 & CVE-2026-53483: Dell PowerProtect Full Takeover (9.8) #DailyCyberSecurity (Jul 14) https://securityonline.info/cve-2026-53483-take-complete-control-system/

    Post summary

    Two high‑severity CVEs in Dell PowerProtect have been disclosed, allowing a full takeover of the system, though no exploit code, active exploitation evidence, or remediation information is provided.

    00000261
    4.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSdelldata_domain_operating_system---

Explore more