AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-41122

HIGH · CVSS 7.1 EPSS 0.22% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

Dell PowerProtect Data Domain products, specifically versions 7.7.1.0 through 8.7 and various LTS releases, are vulnerable to a stored cross-site scripting flaw that allows unauthenticated remote attackers to exploit the system. Successful exploitation could result in information disclosure, session theft, or client-side request forgery. Organizations using these versions should prioritize remediation to mitigate the risk of potential attacks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-41122
Severity
HIGH
CVSS
7.1
EPSS
0.22%

Original NVD Description

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain a stored cross-site scripting vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability. Exploitation may lead to information disclosure, session theft, or client-side request forgery.

Related CVEs

Other vulnerabilities affecting the same vendor(s)