CVE-2026-68861

Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

  • Published Aug 26, 2026
  • CVSS 8.8 high
  • 1.7% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-68861 at the National Vulnerability Database