What is CVE-2026-46737?
Dell PowerProtect Data Manager versions prior to 20.2.0.0 contain an Improper Input Validation vulnerability in the REST API. A remote attacker with high privileges could exploit this to achieve Remote execution. Updating to the latest version is strongly recommended.
Azərbaycanca: Dell PowerProtect Data Manager proqramının 20.2.0.0-dən əvvəlki versiyalarında REST API-də düzgün olmayan daxiletmə yoxlaması (Improper Input Validation) zəifliyi aşkar edilib. Bu boşluq uzaqdan yüksək imtiyazlı təcavüzkara koddan uzaqdan icraya (Remote execution) səbəb ola bilər. Mütləq proqramı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-20; shared vendor: Dell
FAQ2
What is the patched version for Dell PowerProtect Data Manager?
CVE-2026-46737 is resolved in version 20.2.0.0. You must update the application to this version or later.
What can an attacker who exploits this vulnerability achieve?
A remote attacker with high privileges can exploit the Improper Input Validation in the REST API to achieve Remote execution.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.