CVE-2026-70419

Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.

  • Published Aug 26, 2026
  • CVSS 9.1 critical
  • 2.0% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-70419 at the National Vulnerability Database