TL;DR
Dell patched five vulnerabilities in Cloud Disaster Recovery. The most serious, CVE-2026-70419, scores CVSS 9.1 and allows command execution. Several flaws affect versions 20.2 and prior. Update to CDR 20.3 now.
- Total: 3 CVEs
- Severity: 1 Critical · 1 High · 1 Medium
- Actively exploited: None confirmed
- Highest severity: 9.1 (Critical · CVSSv3) — CVE-2026-70419
- Action: Apply the latest security updates now
Notable CVEs
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-70419 | 9.1 | CWE-78 | CDR 20.3 | Not exploited |
| CVE-2026-71171 | 7.2 | CWE-78 | CDR 20.3 | Not exploited |
| CVE-2026-71172 | 4.3 | CWE-918 | CDR 20.3 | Not exploited |
Why These Dell Vulnerabilities Matter
Cloud Disaster Recovery protects backups and failover for enterprise systems. Attackers value recovery tools, since they hold critical data. A Dell vulnerability here can undermine the very safety net customers rely on.
The top flaw scores 9.1, marking it critical. Because it can lead to command execution, the impact is severe. Most bugs, however, require a high-privileged attacker with remote access.
How the Attacks Work
The lead flaw is an OS command injection bug, tracked as CVE-2026-70419. Dell says a high-privileged remote attacker could exploit it, leading to Command execution.
A related REST API bug, CVE-2026-71171, allows remote execution the same way.
Other issues broaden the risk. CVE-2026-68865 is a separate remote code execution flaw. CVE-2026-71173 is a path traversal bug from poor file-path validation. Finally, CVE-2026-71172 is a server-side request forgery flaw that a low-privileged attacker can reach.
Is It Being Exploited?
No exploitation in the wild has been confirmed. Dell reports no active attacks. Likewise, no public proof-of-concept exists yet.
Affected Versions
All five flaws affect Dell Cloud Disaster Recovery versions 20.2 and prior. The command injection and RCE bugs need high privileges, while the SSRF bug needs only low privileges.
Patch and Mitigation Steps
Update Dell Cloud Disaster Recovery to version 20.3 now. No workaround is listed, so upgrading is the recommended fix.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!