CVE-2026-79939CWE-61

CVE-2026-79939

Medium · published August 27, 2026

CVSS v3.1
5.8
EPSS
0%
Percentile
2.4
In the wild
Unconfirmed
What it is

Dell PowerProtect Cyber Recovery, versions Prior to 20.3, contain an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Script injection.

The record
Technical detail
CVSS v3.1
5.8 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L
CVSS v4.0
Not supplied
EPSS
0.00124 · 2.4th percentile
Weakness
CWE-61 · UNIX Symbolic Link (Symlink) Following
Published
2026-08-27T00:18Z
Affected products (1)
ProductVersionsFixed in
dell/powerprotect_cyber_recovery< 20.3.0.020.3.0.0
References (1)
EPSS history
Timeline
  • 28 AUG 06:53Z
    EPSS moved — → 0%
    epss
  • 26 AUG 19:32Z
    Dell PowerProtect Cyber Recovery, versions Prior to 20.3, contain an UNIX Symbolic Link (Symlink) Following vulnerability
    cvelistv5