CVE-2026-40714 – Dell PowerProtect Data Manager
“Security controls are only as strong as the validation behind them.”
This patch addresses multiple vulnerabilities in Dell PowerProtect Data Manager prior to version 20.2.0.0. The update resolves improper input validation flaws in the REST API and related components, as well as an incorrect security token generation issue in the Identity and Access Management (IAM) component. Successful exploitation could allow authenticated remote attackers to elevate privileges within the application.
CVE-2026-40712 has a CVSS score of 9.1, Critical severity. CVE-2026-46738 has a CVSS score of 9.1, Critical severity. CVE-2026-49499 has a CVSS score of 8.8, High severity. CVE-2026-40714 has a CVSS score of 7.2, High severity. No verified real-world exploitation or public proof-of-concept activity has been confirmed for these vulnerabilities.
Key Details
- Affected Product
- Dell Powerprotect Data Manager
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- High
- User Interaction
- None
- CWE Classification
- CWE-20