Dell TechnologiesCVE-2026-71171
Dell Technologies Cloud Disaster Recovery: command injection
High7.2CVE-2026-71171 · Published Aug 26, 2026 · updated Sep 3, 2026
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Cloud Disaster Recovery Product | < CDR 20.3 | CDR 20.3 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-78
More Dell Technologies advisories
All Dell Technologies| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 26 | Dell Technologies Cyber Recovery: improper authentication | High7.6 | Power Protect Cyber Recovery 20.3.0.0+2 more |
| Aug 26 | Dell PowerProtect Cyber Recovery | Medium5.8 | Power Protect Cyber Recovery 20.3.0.0+2 more |
| Aug 26 | Dell Technologies Cloud Disaster Recovery: server-side request forgery | Medium4.3 | CDR 20.3 |
| Aug 26 | Dell Technologies PowerProtect One: command injection | High8.8 | 20.3.0.0 |
| Aug 26 | Dell Technologies PowerProtect One: tampering | Medium6.5 | 20.3.0.0 |
| Aug 26 | Dell Technologies PowerProtect One: improper certificate validation | Medium5.9 | 20.3.0.0 |