Dell PowerProtect One <=20.1.0.0 Auth Bypass via UserControlled Key
CVE-2026-74771 Published on August 26, 2026
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Authorization Bypass Through User-Controlled Key vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering.
Vulnerability Analysis
CVE-2026-74771 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, a high impact on integrity, and no impact on availability.
Weakness Type
What is an Insecure Direct Object Reference / IDOR Vulnerability?
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
CVE-2026-74771 has been classified to as an Insecure Direct Object Reference / IDOR vulnerability or weakness.
Affected Versions
Dell PowerProtect One:- Before 20.3.0.0 is affected.