Dell PowerProtect Data Domain appliances, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper privilege management vulnerability in IDRAC. A high privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges to access unauthorized delete operation in IDRAC.
Use CWE-269, Dell vendor hub and Data Domain Operating System product page to widen CVE-2026-35154 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-26944, CVE-2026-26354 and CVE-2026-26943 for nearby disclosures in the same product family. Additional editorial context is available in The Weekly Cybersecurity Brief: February 27th, 2026.