CVE-2026-53483 – Dell PowerProtect Data Domain
“Critical infrastructure deserves immediate attention when authentication and file access controls fail.”
This update addresses two Critical vulnerabilities affecting Dell PowerProtect Data Domain. CVE-2026-53481 has a CVSS score of 9.8, Critical severity. It is a Path Traversal vulnerability (CWE-22) that allows an unauthenticated remote attacker to gain unauthorized access by exploiting improper restriction of file paths. CVE-2026-53483 also has a CVSS score of 9.8, Critical severity. It is an Improper Authentication vulnerability (CWE-287) that could allow an unauthenticated remote attacker to bypass authentication and gain unauthorized access. No verified real-world exploitation has been reported for either vulnerability.
Both vulnerabilities affect Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7, LTS2026 versions 8.6.1.0 through 8.6.1.10, LTS2025 versions 8.3.1.0 through 8.3.1.30, and LTS2024 versions 7.13.1.0 through 7.13.1.70. Successful exploitation could allow an attacker to take complete control of an affected system. While neither vulnerability is identified as Remote Code Execution (RCE), both have Elevation of Privilege (EoP) characteristics because they enable unauthorized system access. Dell recommends upgrading affected systems as soon as possible.
Key Details
- Affected Product
- Dell Data Domain Operating System
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-287