T
Threats
Dell PowerProtect Data Manager Critical Vulnerabilities
Overview
CVE: CVE-2026-40712, CVE-2026-46738
Severity: Critical
Date: 24 July 2026
Affected Versions
Affected: Dell PowerProtect Data Manager versions prior to 20.2.0.0
Fixed: 20.2.0.0 and later
Vulnerability Breakdown
CVE-2026-40712 - Improper Input Validation (REST API)
Severity: Critical
CVSS: 9.1
Description: Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contains an improper input validation vulnerability in the REST API.
Impact: A high-privileged attacker with remote access could exploit this vulnerability to elevate privileges.
Conditions: Remote access with high-level privileges required.
Notes: No additional vendor nuance provided.
CVE-2026-46738 - Improper Input Validation (REST API)
Severity: Critical
CVSS: 9.1
Description: Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contains a second improper input validation vulnerability in the REST API.
Impact: A high-privileged attacker with remote access could exploit this vulnerability to elevate privileges.
Conditions: Remote access with high-level privileges required.
Notes: No additional vendor nuance provided.
Mitigation
Upgrade Dell PowerProtect Data Manager to version 20.2.0.0 or later immediately.
Restrict REST API access to trusted administrative networks only.
Enforce MFA and least-privilege access for all administrative accounts.
Review REST API access logs for signs of unauthorised elevation attempts.
Summary for IT Teams
Products: Dell PowerProtect Data Manager
Threat Level: Critical, CVSS 9.1
Action Required: Upgrade to version 20.2.0.0 or later immediately and restrict REST API access to trusted administrators.
Reference
Need Help?
Please get in touch on 1300 769 460 or email us. Secure ISS is here to help you strengthen your cybersecurity posture.

