CVE-2026-22266CWE-146

Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Improper Verification of Source of a Communication Channel vulnerability in the REST…

Medium · published February 19, 2026

CVSS v3.1
4.7
EPSS
0%
Percentile
19.5
In the wild
Unconfirmed
What it is

Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Improper Verification of Source of a Communication Channel vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.

The record
Technical detail
CVSS v3.1
4.7 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
CVSS v4.0
Not supplied
EPSS
0.00275 · 19.5th percentile
Weakness
CWE-146 · Improper Neutralization of Expression/Command Delimiters
Published
2026-02-19T09:06Z
EPSS history
Timeline
  • 19 FEB 09:06Z
    Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Improper Verification of Source of a Communication Channel vulnerability in the REST…
    cvelistv5