Skip to content
Dell TechnologiesCVE-2026-49499

Dell PowerProtect Data Manager

High8.8CVE-2026-49499 · Published Jul 22, 2026 · updated Jul 29, 2026

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnerability in the IAM. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

Dell Technologies advisory

Affected versions

PackageAffectedFixed in
PowerProtect Data Manager
Product
< 20.2.0.0 or later20.2.0.0 or later
Details and references

More Dell Technologies advisories

All Dell Technologies
Advisory
Dell Technologies PowerProtect Data Manager: improper input validation
Medium6.7Jul 22
Dell Technologies PowerProtect Data Manager: improper input validation
Critical9.1Jul 22
Dell Technologies PowerProtect Data Manager: information disclosure
Medium6.0Jul 22
Dell Technologies PowerProtect Data Manager: improper input validation
Critical9.1Jul 22
Dell Technologies PowerProtect Data Manager: improper input validation
High7.2Jul 22
Dell Technologies ThinOS 10: protection mechanism failure
Medium6.1Jul 15

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.