CVE-2026-26358

8.8

Dell · Unisphere for PowerMax

Dell Unisphere for PowerMax version 10.2 contains a missing authorization vulnerability that allows a low privileged remote attacker to gain unauthorized access to the system.

Executive summary

A missing authorization vulnerability in Dell Unisphere for PowerMax allows low privileged remote attackers to gain unauthorized access, posing a significant risk to storage management integrity.

Vulnerability

This is a missing authorization flaw (CWE-862) that occurs when the application fails to verify the permissions of a user before granting access to sensitive functions. An attacker with low privileges and remote network access can exploit this to achieve total impact on confidentiality, integrity, and availability.

Business impact

The exploitation of this vulnerability could lead to a complete compromise of the storage management environment. With a CVSS score of 8.8, this flaw presents a high risk, as unauthorized access to PowerMax storage could result in data exfiltration, unauthorized configuration changes, or total loss of service, causing severe operational disruption and potential regulatory non-compliance.

Remediation

Immediate Action: Upgrade to Dell Unisphere for PowerMax version 10.3.0.1 or later as specified in the vendor security advisory.

Proactive Monitoring: Audit system access logs for unusual administrative activity or unauthorized attempts to access management endpoints by low privileged accounts.

Compensating Controls: Restrict network access to the Unisphere management interface to trusted administrative workstations only, utilizing VPNs or firewalls to limit exposure to remote threats.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS score and the critical nature of storage management infrastructure, organizations should prioritize patching this vulnerability immediately. Administrators must transition to version 10.3.0.1 or higher to ensure proper authorization controls are enforced, thereby mitigating the risk of unauthorized access by low privileged users.

More Dell CVEs

Sources