Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2655+ Articles
165+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. Security
  3. CVE-2026-73600: Dell PowerProtect Data Manager Stack Buffer Overflow
CVE-2026-73600: Dell PowerProtect Data Manager Stack Buffer Overflow
SECURITYHIGHCVE-2026-73600

CVE-2026-73600: Dell PowerProtect Data Manager Stack Buffer Overflow

A stack buffer overflow in Dell PowerProtect Data Manager's file-level restore agent lets a high-privileged attacker trigger information disclosure.

Dylan H.

Security Team

September 4, 2026
3 min read

Affected Products

  • Dell PowerProtect Data Manager 20.2.0.0 and earlier

Overview

Dell has disclosed CVE-2026-73600, a stack-based buffer overflow (CWE-121) affecting the file-level restore agent in PowerProtect Data Manager, versions 20.2.0.0 and earlier. The flaw was published to the CVE database on September 3, 2026, and is documented in Dell's advisory DSA-2026-368, which also covers three related vulnerabilities in the same product line.

PowerProtect Data Manager is Dell's enterprise data-protection and backup orchestration platform, widely deployed to manage backup, recovery, and disaster-recovery workflows for virtual machines, databases, and file systems. A flaw in its restore agent puts organizations' backup infrastructure — often the last line of defense against ransomware — directly in the blast radius.


Technical Details

FieldValue
CVE IDCVE-2026-73600
CWECWE-121: Stack-Based Buffer Overflow
SeverityHigh
CVSS 3.1 Score7.8
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected ComponentFile-level restore agent
ImpactInformation disclosure
Affected Versions≤ 20.2.0.0
Fixed Version20.3.0.0

How It Works

Dell's advisory describes the issue as a buffer overflow triggered while the file-level restore agent handles platform language code (PlatformLangCodes) input. The CVSS vector indicates the attack vector is local (AV:L) and requires low privileges (PR:L) with no user interaction — meaning an attacker needs some level of existing access to the host running the restore agent to trigger the overflow. Successful exploitation carries a high impact across confidentiality, integrity, and availability, and Dell's summary describes the primary consequence as information disclosure.


Other Vulnerabilities in DSA-2026-368

Dell's advisory bundles four vulnerabilities affecting the same PowerProtect Data Manager versions, all remediated in the 20.3.0.0 release:

CVECVSS ScoreSeverity
CVE-2026-736007.8High
CVE-2026-688606.8High
CVE-2026-747696.5High
CVE-2026-747684.1Medium

Impact Assessment

Who Is At Risk

Any organization running PowerProtect Data Manager 20.2.0.0 or earlier is affected. Because the restore agent typically runs with elevated access to backup data and connected storage targets, a successful exploit could expose sensitive information contained in backup catalogs or restore workflows — an especially damaging outcome for organizations that rely on PowerProtect as part of their ransomware-recovery strategy.

Attack Prerequisites

  • Existing local or low-privileged access to a system running the affected restore agent
  • No user interaction required once that access is established

Mitigation

Immediate Actions

  • Upgrade to PowerProtect Data Manager 20.3.0.0, which remediates all four vulnerabilities disclosed in DSA-2026-368
  • Review access controls on hosts running the file-level restore agent to limit who can reach it locally
  • Audit backup infrastructure logs for unexpected restore-agent crashes or anomalous behavior consistent with overflow exploitation attempts

Defence-in-Depth

  • Restrict administrative and local access to backup management infrastructure to a minimal set of trusted operators
  • Keep backup software on a supported, current release track — backup platforms are increasingly targeted as part of ransomware kill chains
  • Monitor Dell Security Advisories for follow-up guidance on this product line

References

  • Dell DSA-2026-368: Security Update for Dell PowerProtect Data Manager Multiple Vulnerabilities
  • NVD — CVE-2026-73600
#Dell#PowerProtect#CVE-2026-73600#Buffer Overflow#Backup Security#Information Disclosure

Related Articles

CVE-2026-53483: Dell PowerProtect Data Domain Authentication Bypass — CVSS 9.8

A critical authentication bypass in Dell PowerProtect Data Domain allows unauthenticated remote attackers to gain access to the backup platform. Combined...

6 min read

CVE-2026-53481: Dell PowerProtect Data Domain Path Traversal — CVSS 9.8

A critical path traversal vulnerability in Dell PowerProtect Data Domain backup appliances allows authenticated low-privilege users to read and write...

5 min read

CVE-2026-49814: Dell PowerProtect Data Domain OS Command Injection

A high-severity OS command injection vulnerability in Dell PowerProtect Data Domain allows authenticated remote attackers to execute arbitrary commands...

3 min read
Back to all Security Alerts