CVE-2026-22769

Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as...

Basic Information

CVE State
PUBLISHED
Reserved Date
January 09, 2026
Published Date
February 17, 2026
Last Updated
February 26, 2026
Vendor
Dell
Product
RecoverPoint for Virtual Machines
Description
Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an unauthenticated remote attacker with knowledge of the hardcoded credential could potentially exploit this vulnerability leading to unauthorized access to the underlying operating system and root-level persistence. Dell recommends that customers upgrade or apply one of the remediations as soon as possible.
Tags
cisa

CVSS Scores

CVSS v3.1

10.0 - CRITICAL

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

SSVC Information

Exploitation
active
Automatable
Yes
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (2026-06-01 10:59:33 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CVE 2026-06-01 10:59:33 UTC

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel