Sceawere
Vulnerability Detail
CVE-2026-79938UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Dell PowerProtect Improper Authentication
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.6
- Creation Date
- 3h ago
- Vendor
- Dell
- Product
- Power Protect Cyber Recovery
- Attack Type
- CWE-287: Improper Authentication
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.6",
"pubDate": "2026-08-26T20:18:14.140Z",
"pubdate": "2026-08-26T20:18:14.140Z",
"executiveSummary": "Dell PowerProtect Cyber Recovery versions prior to 20.3 are susceptible to an Improper Authentication vulnerability. This flaw resides within the authentication logic of the application, allowing an attacker to bypass established security controls.\nThe vulnerability is categorized as an improper authentication issue, which may result in unauthorized access to sensitive system functions or data.\nThe attack surface is exposed to any remote user with low-level privileges, meaning an attacker does not require administrative credentials to initiate an exploit attempt.\nThe risk implication is significant, as successful exploitation enables an unauthorized actor to interact with the application in ways that may compromise the integrity or confidentiality of the backup and recovery environment.\nThere are no specific requirements for physical access; the vulnerability is remotely exploitable, necessitating immediate attention to patching protocols to prevent potential unauthorized access.",
"technicalDetails": "The root cause of the vulnerability in Dell PowerProtect Cyber Recovery (versions prior to 20.3) is an Improper Authentication flaw. This occurs when the application fails to adequately verify the credentials or session tokens presented by a user during the authentication handshake process.\nIn a standard deployment, the authentication mechanism is designed to enforce strict session management and identity verification. However, this implementation incorrectly validates user requests, allowing a remote attacker—even one with restricted or low-privileged access—to manipulate the authentication flow.\nThe attack flow typically involves an attacker interacting with the network-facing interfaces of the PowerProtect Cyber Recovery software. By submitting crafted requests that circumvent the intended validation logic, the attacker can successfully establish a session or interact with privileged application functions without providing valid, high-level administrative credentials.\nBecause the vulnerability exists in the handling of authentication assertions, the application fails to distinguish between legitimate requests and those submitted by unauthorized parties. This essentially grants the attacker the permissions associated with a session they have forcibly initiated, leading to unauthorized access.\nThe vulnerable component involves the internal modules responsible for session validation and access control enforcement. Since the flaw is present in the underlying authentication framework of versions prior to 20.3, any deployment using these versions is susceptible to remote exploitation via standard network protocols used by the application.\nPost-exploitation, an attacker could potentially gain unauthorized access to the management console, view recovery configurations, or alter settings, depending on the scope of the authentication bypass. This type of vulnerability is critical in security-centric products like Dell PowerProtect Cyber Recovery, where the confidentiality and integrity of recovery data are paramount.\nThe lack of proper cryptographic verification or consistent state checks during the authentication process allows the attacker to maintain persistence or conduct further lateral movement within the management plane. Remediation requires an upgrade to version 20.3 or later to ensure that the authentication logic is patched to correctly enforce verification protocols."
}