CVE-2026-49499

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/07/2026
Last modified:
29/07/2026

Description

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnerability in the IAM. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dell:powerprotect_data_manager:*:*:*:*:*:*:*:* 20.2 (excluding)