Skip to content
Dell TechnologiesCVE-2026-23501

Dell Technologies RecoverPoint for Virtual Machines: command injection

High7.2CVE-2026-23501 · Published Aug 19, 2026 · updated Aug 20, 2026

Dell RecoverPoint for VMs, versions 6.0.3 and 6.0.3.1, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.

Dell Technologies advisory

Affected versions

PackageAffectedFixed in
RecoverPoint for Virtual Machines
Product
< 6.16.1
Details and references

More Dell Technologies advisories

All Dell Technologies
Advisory
Dell Technologies OpenManage Enterprise: SQL injection
High8.8Aug 19
Dell Command Update (DCU): improper authorization
Medium5.5Aug 19
Dell Command Update (DCU): information disclosure
Medium5.5Aug 19
Dell Command Update (DCU): XML external entity
Medium6.5Aug 19
Dell Command Update (DCU): missing authorization
High8.8Aug 19
Dell Command Update (DCU): missing authorization
High7.3Aug 19

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.