---
id: CVE-2026-49815
title: >-
  Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release
  version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through
  8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an
  improper neut…
summary: >-
  Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release
  version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through
  8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an
  improper neut…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
published: '2026-07-03'
updated: '2026-07-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-49815'
references:
  - url: >-
      https://www.dell.com/support/kbdoc/en-us/000481268/dsa-2026-278-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities
    label: security_alert@emc.com
tags:
  - nvd
ingestedAt: '2026-07-04T10:56:04.349Z'
epss: 0.01712
epssPercentile: 0.76363
---

## Overview

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neutralization of special Elements used in an OS command ('OS command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to execution of arbitrary OS commands.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
