CVE-2026-70419 – Dell Cloud Disaster Recovery
CVSS 9.1
CRITICAL
Critical - Same Day Deployment
“High-privileged remote access can be turned into operating-system command execution on affected disaster recovery systems.”
Dell Cloud Disaster Recovery 20.2 and earlier contain two OS command injection vulnerabilities. CVE-2026-70419 allows a high-privileged remote attacker to execute commands on the affected system. The CVSS score is 9.1, which is Critical severity.
CVE-2026-71171 affects the REST API and can also allow a high-privileged remote attacker to achieve remote command execution. The CVSS score is 7.2, which is High severity.
Key Details
- Affected Product
- Dell Cloud Disaster Recovery
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- High
- User Interaction
- None
- CWE Classification
- CWE-78
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.