Dell PowerProtect Data Domain Multiple Vulnerabilities: Improper Authentication (CVE-2026-53483) and Path Traversal (CVE-2026-53481) Allow Full Remote System Access — Threadlinqs Intelligence
As of 2026-07-15, Dell PowerProtect Data Domain Multiple Vulnerabilities: Improper Authentication (CVE-2026-53483) and Path Traversal (CVE-2026-53481) Allow Full Remote System Access is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 24 indicators of compromise.
Threat ID: TL-2026-1371 · Severity: CRITICAL · CVSS: 9.8 · Status: PATCHED · Category: VULNERABILITY
Dell disclosed two critical (CVSS 9.8) unauthenticated remote vulnerabilities in PowerProtect Data Domain / DD OS: an improper authentication flaw (CVE-2026-53483, CWE-287) and a path traversal flaw
On July 7, 2026, Dell published Security Advisory DSA-2026-278 disclosing two critical vulnerabilities in Dell PowerProtect Data Domain, Data Domain Virtual Edition, Dell APEX Protection Storage, and Data Domain Management Center. Both flaws carry the maximum practical CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), meaning they are remotely exploitable over the network, require no authentication, no privileges, and no user interaction, and yield complete compromise of confidentiality, integrity, and availability.
CVE-2026-53483 is an Improper Authentication vulnerability (CWE-287) in the DD OS management/administration interface. An unauthenticated attacker with network access to the appliance can bypass authentication controls to gain unauthorized device access, potentially achieving full administrative control of the Data Domain system without ever presenting valid credentials.
CVE-2026-53481 is a Path Traversal vulnerability (CWE-22, Improper Limitation of a Pathname to a Restricted Directory) in DD OS, also exploitable by an unauthenticated remote attacker. Path traversal in a backup-storage OS context is particularly severe: it can allow reads/writes outside the intended restricted directory tree, exposing configuration data, credential material, backup catalogs, or enabling the attacker to place or overwrite files used to escalate to full system compromise.
Because Data Domain appliances function as the last line of defense for enterprise backup and recovery data, an unauthenticated attacker chaining or independently exploiting either flaw could tamper with or destroy backup integrity, exfiltrate sensitive backed-up data, and disable an organization's ransomware-recovery capability -- a high-value target profile consistent with pre-ransomware "backup poisoning" operations observed against other backup/storage vendors industry-wide.
Both CVEs affect DD OS release versions 7.7.1.0 through 8.7.0.0, as well as the LTS2024 (7.13.1.0-7.13.1.70), LTS2025 (8.3.1.0-8.3.1.30), and LTS2026 (8.6.1.0-8.6.1.10) long-term-support branches. Dell credits external researcher Ahmed Y. Elmogy for responsibly reporting both issues. As of publication, Dell states no active exploitation in the wild and no public proof-of-concept exploit code; the vulnerabilities were disclosed coordinated with patch availability. Fixed versions are DD OS 8.8.0.0 (or 8.7.0.0+ per Dell's general release track), 8.6.1.20 (LTS2026), 8.3.1.40 (LTS2025), and 7.13.1.80 (LTS2024).
Weaknesses (CWE)
CWE-287, CWE-22
Target sectors: government administration, finance, health, technology, manufacturing, critical-infrastructure, energy, education, retail, telecoms
Target regions: North America, Europe, Asia Pacific, Global
Detections & IOCs
As of 2026-08-10, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 24 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-53483, CVE-2026-53481, T1595, T1592, T1190, T1212, T1211, T1083, T1082, T1046, T1005, T1213