---
id: CVE-2026-41123
title: >-
  Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release
  version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through
  8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an
  improper acce…
summary: >-
  Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release
  version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through
  8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an
  improper acce…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-284
published: '2026-07-03'
updated: '2026-07-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-41123'
references:
  - url: >-
      https://www.dell.com/support/kbdoc/en-us/000481268/dsa-2026-278-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities
    label: security_alert@emc.com
tags:
  - nvd
ingestedAt: '2026-07-04T07:55:53.918Z'
epss: 0.00254
epssPercentile: 0.15149
---

## Overview

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper access control vulnerability in the RBAC. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to information tampering.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
