Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
widely-deployed-product-advisoryidentity-authentication-vulnerabilityembedded-device-vulnerabilityperimeter-device-exposure

Dell Patches Critical Authentication and Command Injection Flaws Across Storage Products

Updated 11d agoFirst seen Jun 12, 202615 sources

Dell disclosed multiple high-severity vulnerabilities affecting enterprise storage and backup platforms, including PowerProtect Data Domain, Storage Manager, and Unity. In PowerProtect Data Domain, CVE-2026-26944 allows unauthenticated remote attackers to reach a privileged function and potentially execute commands as root if a legitimate user performs a specific action, while CVE-2026-26943 and CVE-2026-23778 enable root-level command execution for attackers with high privileges. Dell said the issues affect several DD OS release tracks, Data Domain Virtual Edition, APEX Protection Storage, Data Domain Management Center, and PowerProtect DP Series appliances, and released fixes through advisory DSA-2026-060, adding that it had no indication of active exploitation.

Dell also issued critical updates for other storage lines. Dell Storage Manager vulnerabilities CVE-2025-43994 and CVE-2025-43995 expose management functions and APIs to unauthenticated remote access or authentication bypass, potentially affecting all storage arrays managed by a vulnerable instance; Dell’s advisory DSA-2025-393 recommends upgrading to 2020 R1.22 or later. In Dell Unity, CVE-2025-36604 permits unauthenticated remote OS command injection, while CVE-2025-36606 and CVE-2025-36607 allow authenticated attackers to escape restricted utilities and run commands as root; Dell remediated those flaws in Unity OE 5.5.1 and later. The disclosures highlight elevated risk to backup integrity, storage administration, and ransomware recovery operations if exposed management interfaces remain unpatched.

Share:
Dell Patches Critical Authentication and Command Injection Flaws Across Storage Products
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Apr 14, 20262mo ago

Dell publishes DSA-2026-060 for PowerProtect Data Domain vulnerabilities

Dell disclosed security advisory DSA-2026-060 covering CVE-2026-23778, CVE-2026-26943, CVE-2026-26944, and additional vulnerabilities affecting PowerProtect Data Domain products. The advisory provided DD OS and firmware updates across multiple release tracks and stated there was no indication of active exploitation for CVE-2026-26944.

Brief Summary: CVE-2026-26944 Missing Authentication in Dell PowerProtect Data Domain Enables Remote Root Command Execution - ZeroPath Blog | ZeroPath
Nov 17, 20257mo ago

Dell releases patches for ReVault-related ControlVault3 flaws

Dell issued security advisories and coordinated firmware and driver patches for multiple ControlVault3 and ControlVault3 Plus vulnerabilities, including CVE-2025-31361, CVE-2025-31649, CVE-2025-32089, and CVE-2025-36553. The flaws affected more than 100 Dell laptop models and enabled impacts ranging from privilege escalation to firmware-context code execution.

Dell ControlVault3 CVE-2025-31361 Privilege Escalation: Brief Summary and Technical Review - ZeroPath Blog | ZeroPath
Oct 24, 20258mo ago

Dell issues DSA-2025-393 for Storage Manager vulnerabilities

Dell initially released security advisory DSA-2025-393 for Dell Storage Manager on 2025-10-24 and updated it the same day to clarify the remediated version. The advisory covered CVE-2025-43994, CVE-2025-43995, and CVE-2025-46425 and recommended upgrading to version 2020 R1.22 or later.

DSA-2025-393: Security Update for Storage Center - Dell Storage Manager Vulnerabilities | Dell US
Oct 7, 20259mo ago

Dell releases fixes for PowerProtect Data Domain auth bypass CVE-2025-43727

Dell addressed CVE-2025-43727, an authentication bypass in the RestAPI component of PowerProtect Data Domain DD OS, and recommended upgrades to remediated versions across affected release tracks. The flaw allowed unauthenticated remote attackers to send crafted API requests that bypass authentication checks.

Dell PowerProtect Data Domain CVE-2025-43727: Brief Summary of High-Severity Authentication Bypass - ZeroPath Blog | ZeroPath
Aug 4, 202511mo ago

Dell discloses Unity command injection flaws and releases Unity OE 5.5.1

Dell disclosed CVE-2025-36604, CVE-2025-36606, and CVE-2025-36607 affecting Dell Unity, UnityVSA, and Unity XT systems running Unity OE 5.5 and earlier. The company said the issues were fixed in Unity OE 5.5.1 and advised customers to upgrade.

Dell Unity CVE-2025-36604 OS Command Injection: Brief Summary and Patch Guidance - ZeroPath Blog | ZeroPath
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

48 LINKEDOpen in app
Vulnerabilities
32 linked
Missing Authentication Leading to Root Command Execution in Dell PowerProtect Data DomainOS Command Injection in Dell PowerProtect Data Domain DD OSImproper Input Validation in Dell PowerProtect Data Domain DD OS leading to root command executionArgument Injection in Dell PowerProtect Data Domain DD OSOS command injection in Dell PowerProtect Data Domain DD OSOS Command Injection in Dell PowerProtect Data Domain DD OSImproper Input Validation in Dell PowerProtect Data Domain DD OSOS Command Injection in Dell PowerProtect Data Domain DD OSCommand Injection in Dell PowerProtect Data Domain DD OSXXE in Dell Storage Manager 20.1.20Missing Authentication in Dell Storage Manager 20.1.21Authentication Bypass in Dell Storage Manager Data Collector ApiProxyOS Command Injection in Dell Unity svc_nfssupportUnauthenticated OS Command Injection in Dell UnityOut-of-bounds write in Dell ControlVault3 cv_upgrade_sensor_firmwareOut-of-bounds read in Dell ControlVault3 cv_send_blockdataStack-based buffer overflow in Dell ControlVault3 securebio_identifyArbitrary free in Dell ControlVault3 cv_closeAuthentication bypass in Dell PowerProtect Data Domain RestAPIOS Command Injection in Dell Unity svc_nas UtilityUnsafe deserialization in Dell ControlVault3 cvhDecapsulateCmdUntitledHard-coded Password in Dell ControlVault3 WBDI DriverCross-site Scripting in Dell UnityUntitledPrivilege Escalation in Dell ControlVault WBDI Driver WBIO_USH_ADD_RECORDUntitledInsufficient access control in Dell dbutil_2_3.sys driverBuffer Overflow in Dell ControlVault3 CvManagerCommand Injection in Dell PowerProtect Data Domain DD OSStack-based buffer overflow in Dell PowerProtect Data Domain DD OSUntitled
Affected products
7 linked
Data Domain Operating SystemPowerprotect Data ManagerDell Storage ManagerWindowsIdrac9Powerprotect Data DomainPowerprotect Dp Series Appliance
Organizations
9 linked
Dell TechnologiesCisco SystemsPositive TechnologiesTenableBroadcomWatchTowrFeedlyGBHackersUbisectech Sirius Team
SOURCE COVERAGE

Sources

15 references tracked. Mallory keeps watching after this page renders.

15 SOURCESView all
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Dell Patches Critical Authentication and Command Injection Flaws Across Storage Products | Mallory