Skip to content
Dell TechnologiesCVE-2026-71171

Dell Technologies Cloud Disaster Recovery: command injection

High7.2CVE-2026-71171 · Published Aug 26, 2026 · updated Sep 3, 2026

Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

Dell Technologies advisory

Affected versions

PackageAffectedFixed in
Cloud Disaster Recovery
Product
< CDR 20.3CDR 20.3
Details and references

More Dell Technologies advisories

All Dell Technologies
Advisory
Dell Technologies Cyber Recovery: improper authentication
High7.6Aug 26
Dell PowerProtect Cyber Recovery
Medium5.8Aug 26
Dell Technologies Cloud Disaster Recovery: server-side request forgery
Medium4.3Aug 26
Dell Technologies PowerProtect One: command injection
High8.8Aug 26
Dell Technologies PowerProtect One: tampering
Medium6.5Aug 26
Dell Technologies PowerProtect One: improper certificate validation
Medium5.9Aug 26

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.