CVE-2026-71171 – Dell Cloud Disaster Recovery

CVSS 7.2 IMPORTANT Critical - Same Day Deployment

“High-privileged remote access can be turned into operating-system command execution on affected disaster recovery systems.”

Dell Cloud Disaster Recovery 20.2 and earlier contain two OS command injection vulnerabilities. CVE-2026-70419 allows a high-privileged remote attacker to execute commands on the affected system. The CVSS score is 9.1, which is Critical severity.

CVE-2026-71171 affects the REST API and can also allow a high-privileged remote attacker to achieve remote command execution. The CVSS score is 7.2, which is High severity.

Key Details

Affected Product
Dell Cloud Disaster Recovery
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
CWE Classification
CWE-78
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.