CVE-2026-41123
Last modified
CVE-2026-41123 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper access control vulnerability in the RBAC. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to information tampering.. EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper access control vulnerability in the RBAC. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to information tampering.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dell | Data Domain Operating System | >= 7.7.1.0, < 7.13.1.80 |
| Dell | Data Domain Operating System | >= 7.14.0.0, < 8.3.1.40 |
| Dell | Data Domain Operating System | >= 8.4.0.0, < 8.6.1.20 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-41123?
How severe is CVE-2026-41123?
How do I fix CVE-2026-41123?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-41116Dell Inventory Collector Client, versions prior to 13.8.0, c…6.3
- CVE-2026-41119Dell Live Optics Windows and Personal Edition collectors con…6.8
- CVE-2026-4112Improper neutralization of special elements used in an SQL c…7.2
- CVE-2026-41120Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, c…9.8
- CVE-2026-41121Dell Device Management Agent, versions prior to DDMA 26.05, …7.8
- CVE-2026-41122Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7,…7.1
- CVE-2026-41124Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6,…4.4
- CVE-2026-41125A vulnerability has been identified in blueplanet 100 NX3 M8…6
- CVE-2026-41126BigBlueButton is an open-source virtual classroom. Versions …4.3
- CVE-2026-41127BigBlueButton is an open-source virtual classroom. Versions …6.5
- CVE-2026-41128Craft CMS is a content management system (CMS). In versions …5.3
- CVE-2026-41129Craft CMS is a content management system (CMS). Versions on …5.5
Are you affected by CVE-2026-41123?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
