Vulnerability Details CVE-2026-71171
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.01
EPSS Ranking 60.7%
CVSS Severity
CVSS v3 Score 7.2
Products affected by CVE-2026-71171
-
cpe:2.3:a:dell:cloud_disaster_recovery:*