Sceawere
Vulnerability Detail
CVE-2026-49499Updated Verified Sceawere Triage Sources: NVD / CISA KEV
Dell PowerProtect Data Manager IAM Privilege Escalation
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 5h ago
- Vendor
- Dell
- Product
- PowerProtect Data Manager
- Attack Type
- CWE-1270: Generation of Incorrect Security Tokens
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnerability in the IAM. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-07-22T16:17:29.943Z",
"pubdate": "2026-07-22T16:17:29.943Z",
"executiveSummary": "Dell PowerProtect Data Manager contains a Generation of Incorrect Security Tokens vulnerability residing within the Identity and Access Management (IAM) component. This security flaw affects software versions prior to 20.2.0.0 and introduces significant risk to enterprise backup infrastructures by allowing unauthorized privilege escalation.\nAn authenticated low-privileged remote attacker capable of network access to the target system can potentially exploit this vulnerability to elevate their assigned privileges. Successful exploitation allows the adversary to bypass intended access control boundaries, assuming higher-level roles and permissions within the affected application.\nThe risk implications include unauthorized access to sensitive backup data management functions, administrative capabilities, and underlying system controls. Mitigation requires applying the official vendor-supplied software updates provided by Dell to resolve the underlying cryptographic or token generation flaws within the IAM subsystem.",
"technicalDetails": "The vulnerability is classified as a Generation of Incorrect Security Tokens flaw, located within the Identity and Access Management (IAM) component of Dell PowerProtect Data Manager versions prior to 20.2.0.0.\nThe root cause stems from improper implementation or flawed logic during the creation, signing, validation, or handling of security tokens utilized for session management and authorization within the IAM subsystem. When security tokens are generated with insufficient entropy, incorrect cryptographic parameters, or flawed claims validation, the system fails to adequately bind the token to the issuing security context.\nExploitation requires network exposure to the vulnerable Dell PowerProtect Data Manager instance and low-privileged remote access. The attack flow proceeds as follows: First, the low-privileged attacker establishes a standard authenticated session within the application. Second, leveraging the flawed token generation mechanism in the IAM component, the attacker manipulates, crafts, or intercepts authentication and authorization tokens. Because the system improperly validates or generates these tokens, it misinterprets the claims or privilege levels asserted within the modified token.\nUpon successful processing of the improperly generated or manipulated security token by the IAM component, the application grants the attacker elevated privileges corresponding to a higher-tier administrative or privileged role. This bypasses the standard role-based access control (RBAC) mechanisms enforced by the software.\nThe post-exploitation impact includes full unauthorized access to administrative functionalities, manipulation of data protection policies, potential exposure of enterprise backup data, and full control over the affected Dell PowerProtect Data Manager environment."
}