CVE-2026-40712

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
22/07/2026
Last modified:
29/07/2026

Description

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dell:powerprotect_data_manager:*:*:*:*:*:*:*:* 20.2 (excluding)