What is CVE-2026-49499?
This critical vulnerability in Dell PowerProtect Data Manager versions prior to 20.2.0.0 involves the generation of incorrect security tokens within the IAM component. A low-privileged attacker with remote access could exploit this flaw to achieve privilege escalation. Affected systems should be immediately updated to version 20.2.0.0 or later.
Azərbaycanca: Bu kritik zəiflik Dell PowerProtect Data Manager proqramının 20.2.0.0 versiyasından əvvəlki versiyalarında İAM komponentində səhv təhlükəsizlik tokenlərinin yaradılması ilə bağlıdır. Aşağı səlahiyyətli uzaqdan girişi olan hücumçu bu boşluqdan istifadə edərək imtiyaz yüksəlişi əldə edə bilər. Təsirə məruz qalan sistemlərin dərhal 20.2.0.0 və ya daha yeni versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: shared vendor: Dell
FAQ2
Which versions of Dell PowerProtect Data Manager are vulnerable to CVE-2026-49499?
Versions of Dell PowerProtect Data Manager prior to 20.2.0.0 are vulnerable to this flaw.
What can an attacker achieve by successfully exploiting CVE-2026-49499?
A low-privileged attacker with remote access could exploit the incorrect security token generation in the IAM component to achieve privilege escalation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.