CVE-2026-46738 – Dell PowerProtect Data Manager

CVSS 9.1 CRITICAL Critical - Same Day Deployment

“Security controls are only as strong as the validation behind them.”

This patch addresses multiple vulnerabilities in Dell PowerProtect Data Manager prior to version 20.2.0.0. The update resolves improper input validation flaws in the REST API and related components, as well as an incorrect security token generation issue in the Identity and Access Management (IAM) component. Successful exploitation could allow authenticated remote attackers to elevate privileges within the application.

CVE-2026-40712 has a CVSS score of 9.1, Critical severity. CVE-2026-46738 has a CVSS score of 9.1, Critical severity. CVE-2026-49499 has a CVSS score of 8.8, High severity. CVE-2026-40714 has a CVSS score of 7.2, High severity. No verified real-world exploitation or public proof-of-concept activity has been confirmed for these vulnerabilities.

Key Details

Affected Product
Dell Powerprotect Data Manager
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
CWE Classification
CWE-20
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.