---
id: CVE-2026-46465
title: >-
  Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release
  version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through
  8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an use
  of extern…
summary: >-
  Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release
  version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through
  8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an use
  of extern…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H'
cwe:
  - CWE-134
published: '2026-07-03'
updated: '2026-07-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-46465'
references:
  - url: >-
      https://www.dell.com/support/kbdoc/en-us/000481268/dsa-2026-278-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities
    label: security_alert@emc.com
tags:
  - nvd
ingestedAt: '2026-07-04T10:56:04.286Z'
epss: 0.00408
epssPercentile: 0.34834
---

## Overview

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an use of externally-controlled format string vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure and denial of service.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
