Dell PowerProtect Data Domain Multiple Vulnerabilities: Improper Authentication (CVE-2026-53483) and Path Traversal (CVE-2026-53481) Allow Full Remote System Access

Dell PowerProtect Data Domain Multiple Vulnerabilities (TL-2026-1371), also tracked as DSA-2026-278, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-07-15. It has no confirmed attribution, affects Dell PowerProtect Data Domain (DD OS), references 2 CVEs (CVE-2026-53483, CVE-2026-53481), maps to 19 MITRE ATT&CK techniques (T1005, T1046, T1059), and is covered by 9 detection rules and 24 indicators of compromise.

Key facts for TL-2026-1371

Threat ID
TL-2026-1371
Also known as
DSA-2026-278
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
PATCHED
Category
VULNERABILITY
First published
2026-07-15
Last reviewed
2026-07-15
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, finance, health, technology, manufacturing, critical-infrastructure, energy, education, retail, telecoms
Target regions
North America, Europe, Asia Pacific, Global
Detection rules
9
Indicators of compromise
24

Dell disclosed two critical (CVSS 9.8) unauthenticated remote vulnerabilities in PowerProtect Data Domain / DD OS: an improper authentication flaw (CVE-2026-53483, CWE-287) and a path traversal flaw (CVE-2026-53481, CWE-22), either of which can grant an unauthenticated network attacker complete control of the backup appliance. No active exploitation or public PoC has been reported; Dell has released patched DD OS builds.

How Dell PowerProtect Data Domain Multiple Vulnerabilities works

On July 7, 2026, Dell published Security Advisory DSA-2026-278 disclosing two critical vulnerabilities in Dell PowerProtect Data Domain, Data Domain Virtual Edition, Dell APEX Protection Storage, and Data Domain Management Center. Both flaws carry the maximum practical CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), meaning they are remotely exploitable over the network, require no authentication, no privileges, and no user interaction, and yield complete compromise of confidentiality, integrity, and availability.

CVE-2026-53483 is an Improper Authentication vulnerability (CWE-287) in the DD OS management/administration interface. An unauthenticated attacker with network access to the appliance can bypass authentication controls to gain unauthorized device access, potentially achieving full administrative control of the Data Domain system without ever presenting valid credentials.

CVE-2026-53481 is a Path Traversal vulnerability (CWE-22, Improper Limitation of a Pathname to a Restricted Directory) in DD OS, also exploitable by an unauthenticated remote attacker. Path traversal in a backup-storage OS context is particularly severe: it can allow reads/writes outside the intended restricted directory tree, exposing configuration data, credential material, backup catalogs, or enabling the attacker to place or overwrite files used to escalate to full system compromise.

Because Data Domain appliances function as the last line of defense for enterprise backup and recovery data, an unauthenticated attacker chaining or independently exploiting either flaw could tamper with or destroy backup integrity, exfiltrate sensitive backed-up data, and disable an organization's ransomware-recovery capability -- a high-value target profile consistent with pre-ransomware "backup poisoning" operations observed against other backup/storage vendors industry-wide.

Both CVEs affect DD OS release versions 7.7.1.0 through 8.7.0.0, as well as the LTS2024 (7.13.1.0-7.13.1.70), LTS2025 (8.3.1.0-8.3.1.30), and LTS2026 (8.6.1.0-8.6.1.10) long-term-support branches. Dell credits external researcher Ahmed Y. Elmogy for responsibly reporting both issues. As of publication, Dell states no active exploitation in the wild and no public proof-of-concept exploit code; the vulnerabilities were disclosed coordinated with patch availability. Fixed versions are DD OS 8.8.0.0 (or 8.7.0.0+ per Dell's general release track), 8.6.1.20 (LTS2026), 8.3.1.40 (LTS2025), and 7.13.1.80 (LTS2024).

MITRE ATT&CK techniques used in TL-2026-1371

Collection

T1005 Data from Local System; T1213 Data from Information Repositories

Discovery

T1046 Network Service Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery

Execution

T1059 Command and Scripting Interpreter

Privilege Escalation

T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism

Initial Access

T1190 Exploit Public-Facing Application

Defense Evasion

T1211 Exploitation for Stealth

Credential Access

T1212 Exploitation for Credential Access

Impact

T1485 Data Destruction; T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery; T1499 Endpoint Denial of Service; T1561 Disk Wipe

Persistence

T1505 Server Software Component

Reconnaissance

T1592 Gather Victim Host Information; T1595 Active Scanning

Affected products and versions in Dell PowerProtect Data Domain Multiple Vulnerabilities

  • Dell — PowerProtect Data Domain (DD OS)
    Vulnerable versions: 7.7.1.0-8.7.0.0; LTS2024 7.13.1.0-7.13.1.70; LTS2025 8.3.1.0-8.3.1.30; LTS2026 8.6.1.0-8.6.1.10
    Fixed in: 8.8.0.0; 8.7.0.0+ (general release); 7.13.1.80 (LTS2024); 8.3.1.40 (LTS2025); 8.6.1.20 (LTS2026)
  • Dell — Data Domain Virtual Edition
    Vulnerable versions: 7.7.1.0-8.7.0.0
    Fixed in: 8.8.0.0; 8.7.0.0+
  • Dell — APEX Protection Storage
    Vulnerable versions: 7.7.1.0-8.7.0.0
    Fixed in: 8.8.0.0; 8.7.0.0+
  • Dell — Data Domain Management Center
    Vulnerable versions: 7.7.1.0-8.7.0.0
    Fixed in: 8.8.0.0; 8.7.0.0+

Remediation for Dell PowerProtect Data Domain Multiple Vulnerabilities

Patches

  • Upgrade to DD OS 8.8.0.0 (or 8.7.0.0+ general release) to remediate both CVE-2026-53483 and CVE-2026-53481.
  • LTS2026 branch: upgrade to DD OS 8.6.1.20 or later.
  • LTS2025 branch: upgrade to DD OS 8.3.1.40 or later.
  • LTS2024 branch: upgrade to DD OS 7.13.1.80 or later.

Immediate actions

  • Inventory all Dell PowerProtect Data Domain, Data Domain Virtual Edition, APEX Protection Storage, and Data Domain Management Center instances and identify their running DD OS version.
  • Restrict network access to Data Domain management interfaces to trusted management VLANs / jump hosts only; do not expose management interfaces directly to the internet.
  • Apply emergency network ACL/firewall restrictions on the DD OS administration and REST/API ports pending patch deployment.
  • Review authentication logs and file-access logs on Data Domain systems for anomalous unauthenticated administrative sessions or unexpected file path access outside standard directories.

Workarounds

  • No official workaround published by Dell; network isolation and access restriction of the management interface are the only interim mitigations pending patch deployment.
  • Disable or restrict any externally reachable administration service on the Data Domain appliance until patched.

Longer-term hardening

  • Deploy DD OS patches on a defined maintenance cadence tied to Dell Security Advisory releases.
  • Segment backup infrastructure into an isolated, tightly access-controlled network zone (a backup/recovery 'clean room') separate from general production and Active Directory-joined networks.
  • Enable and centrally forward Data Domain audit/authentication logs to a SIEM for continuous monitoring of the backup tier.
  • Implement immutable/air-gapped backup copies (DD Retention Lock or equivalent) so that a compromised Data Domain system cannot be used to destroy all recoverable backup data.
  • Establish a recurring vulnerability-scanning and patch-verification process specifically for backup/storage appliances, which are frequently deprioritized relative to general-purpose servers.

CVEs associated with Dell PowerProtect Data Domain Multiple Vulnerabilities

CVE-2026-53483, CVE-2026-53481

Weaknesses (CWE) in Dell PowerProtect Data Domain Multiple Vulnerabilities

CWE-287, CWE-22

Timeline of Dell PowerProtect Data Domain Multiple Vulnerabilities

  • Dell initially publishes Security Advisory DSA-2026-278 addressing 70+ vulnerabilities (including CVE-2026-53483 and CVE-2026-53481) across PowerProtect Data Domain DD OS and bundled third-party components (Apache Tomcat, OpenSSL, Python, PostgreSQL, Curl).
  • Dell publishes Security Advisory DSA-2026-278 disclosing both vulnerabilities affecting PowerProtect Data Domain, Data Domain Virtual Edition, APEX Protection Storage, and Data Domain Management Center.
  • CVE-2026-53483 (Improper Authentication) and CVE-2026-53481 (Path Traversal) published to NVD with CVSS 9.8 scores.
  • Third-party vulnerability intelligence trackers (THREATINT, VulDB, OpenCVE) index both CVEs, crediting researcher Ahmed Y. Elmogy for responsible disclosure.
  • CVE-2026-53481 record last modified on NVD with finalized CWE-22 classification and affected-version ranges.
  • Dell revises DSA-2026-278 to Revision 3.0, clarifying affected version ranges and remediation guidance for the full CVE set including CVE-2026-56086, CVE-2026-53479, CVE-2026-53482, and CVE-2026-41122.
  • RESEARCH phase analysis completed; no active exploitation or public proof-of-concept exploit code identified as of this date; patched DD OS versions confirmed available from Dell.
  • TL-Intel-Harness HUNT phase surfaces the advisory via RSS ingestion and creates threat skeleton TL-2026-1371 based on the dual CVSS 9.8 network-attack-vector criterion.
  • Cyber Security News publishes coverage summarizing the two critical Dell PowerProtect Data Domain vulnerabilities and urging patch deployment.

Sources cited for Dell PowerProtect Data Domain Multiple Vulnerabilities

Threats related to Dell PowerProtect Data Domain Multiple Vulnerabilities

Detection coverage for TL-2026-1371

As of 2026-07-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1371 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats