CVE-2026-35154 PUBLISHED

Assigner: dell
Reserved: 01.04.2026 Published: 20.04.2026 Updated: 20.04.2026

Dell PowerProtect Data Domain appliances, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper privilege management vulnerability in IDRAC. A high privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges to access unauthorized delete operation in IDRAC.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
CVSS Score: 6.3

Product Status

Vendor Dell
Product PowerProtect Data Domain appliances
Versions Default: unaffected
  • affected from 0 to 8.7.0.1 or later (excl.)
  • affected from 0 to 8.3.1.30 or later (excl.)
  • affected from 0 to 7.13.1.70 or later (excl.)

References

Problem Types

  • CWE-269: Improper Privilege Management CWE