CVE-2026-40712
Dell PowerProtect Data Manager versions before 20.2.0.0 have a flaw in their REST API that lets a remote attacker with high privileges gain elevated access. This could let the attacker take control of the system. The vulnerability is considered critical.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Dell PowerProtect Data Manager, versions prior to 20.2.0.0.
Real-world impact
An attacker could use the flaw to increase their privileges on the system, potentially taking full control of the data manager and accessing or modifying protected data.
Why this severity
The CVSS score of 9.1 reflects that the vulnerability can be exploited remotely with low effort, requires high privileges, and gives an attacker full control over confidentiality, integrity, and availability.
What to do about it
- 01Upgrade Dell PowerProtect Data Manager to version 20.2.0.0 or later.
NVD-referenced vendor advisory
Timeline
- Jul 22, 2026 · 10d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 22, 2026 · 10d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 29, 2026 · 3d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- dell.com/support/kbdoc/en-us/0004888…vendor advisory