Dell PowerProtect Cyber Recovery <20.3 Improper Auth Vulnerability
CVE-2026-79938 Published on August 26, 2026
Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
Vulnerability Analysis
CVE-2026-79938 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality, a high impact on integrity, and a small impact on availability.
Weakness Type
What is an authentification Vulnerability?
When an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.
CVE-2026-79938 has been classified to as an authentification vulnerability or weakness.
Affected Versions
Dell Power Protect Cyber Recovery:- Before 20.3.0.0 is affected.
- Before osupdate-15.4.0-19.bin is affected.
- Before osupdate-15.6.1-1.bin is affected.