Sceawere
Vulnerability Detail
CVE-2026-46738Updated Verified Sceawere Triage Sources: NVD / CISA KEV
Dell PowerProtect Data Manager Improper Input Validation
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.1
- Creation Date
- 5h ago
- Vendor
- Dell
- Product
- PowerProtect Data Manager
- Attack Type
- CWE-20: Improper Input Validation
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.1",
"pubDate": "2026-07-22T16:17:24.223Z",
"pubdate": "2026-07-22T16:17:24.223Z",
"executiveSummary": "An improper input validation vulnerability has been identified in Dell PowerProtect Data Manager in versions prior to 20.2.0.0. This security flaw resides within the REST API component of the application and can be leveraged by a remote adversary to compromise system integrity. Specifically, the vulnerability allows a high-privileged attacker to achieve an elevation of privileges on the affected system.\nThe risk implications associated with this flaw are severe, as successful exploitation enables an authenticated user with elevated privileges to execute unauthorized actions beyond their intended permission boundaries. The exploitation requires remote network access to the target REST API and assumes the attacker has already obtained high-privileged credentials to interact with the vulnerable interface.\nOrganizations utilizing affected versions of Dell PowerProtect Data Manager face potential administrative takeovers or unauthorized system modifications if the management interface is exposed to untrusted networks. Immediate remediation through vendor-supplied software updates is critical to mitigate the risk of privilege escalation and maintain the confidentiality, integrity, and availability of the backup infrastructure.",
"technicalDetails": "The vulnerability is classified as an improper input validation flaw affecting the REST API of Dell PowerProtect Data Manager for versions prior to 20.2.0.0. The root cause stems from the application's failure to adequately sanitize, validate, or filter user-supplied input parameters passed through API endpoints before processing them within internal operational logic or administrative functions.\nThe vulnerable component is the REST API service exposed by Dell PowerProtect Data Manager, which handles administrative requests and system orchestration tasks. The network exposure is remote, meaning an attacker interacts with the target system over the network interface hosting the API services. Exploitation requires the attacker to possess high-privileged credentials, as standard or unprivileged users typically lack access to the specific API functions susceptible to this input validation failure.\nThe step-by-step attack flow proceeds as follows: First, the high-privileged attacker authenticates against the Dell PowerProtect Data Manager REST API using valid administrative or high-tier credentials. Second, the attacker crafts a malicious HTTP request targeting a vulnerable API endpoint, injecting specially crafted payloads designed to bypass input validation routines or manipulate backend processing logic. Third, the REST API processes the improperly validated input, failing to reject or neutralize the malicious parameters. Finally, the improper handling of this data allows the attacker to execute unauthorized administrative operations, resulting in an elevation of privileges within the application environment.\nThe post-exploitation impact includes unauthorized modification of system settings, potential execution of privileged commands, compromise of backup data orchestration controls, and deeper administrative penetration into the underlying architecture managed by Dell PowerProtect Data Manager."
}