# CVE-2026-46465

## Summary

- **CVE ID:** CVE-2026-46465
- **Severity:** MEDIUM
- **CVSS Score:** 5.5 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H)
- **CWE:** CWE-134
- **Published:** Jul 3, 2026
- **Last Modified:** Jul 6, 2026

## Description

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an use of externally-controlled format string vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure and denial of service.

## Affected Products

- Dell — PowerProtect Data Domain (0)

## References

- [CNA](https://www.dell.com/support/kbdoc/en-us/000481268/dsa-2026-278-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.41%
- **EPSS Percentile:** 34.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._