CVE-2026-26359
8.8Dell · Unisphere for PowerMax
Dell Unisphere for PowerMax contains a path traversal vulnerability allowing a low privileged remote attacker to overwrite arbitrary files on the system.
Executive summary
A path traversal vulnerability in Dell Unisphere for PowerMax allows low privileged remote attackers to overwrite arbitrary files, posing a significant risk to system integrity.
Vulnerability
This vulnerability is classified as CWE-73: External Control of File Name or Path. It allows an attacker with low privileges and remote network access to manipulate file paths, potentially resulting in the overwriting of arbitrary files on the host system.
Business impact
Successful exploitation of this flaw could lead to full system compromise, as the ability to overwrite arbitrary files may allow an attacker to modify configuration files, inject malicious code, or disrupt critical storage management services. With a CVSS score of 8.8, this vulnerability represents a high risk to organizational data and infrastructure availability.
Remediation
Immediate Action: Update Dell Unisphere for PowerMax and PowerMax EEM to version 10.3.0.1 or later as specified in the official Dell Security Advisory (DSA-2026-102).
Proactive Monitoring: Review system access logs for suspicious file modification patterns or unauthorized attempts to access directories outside of expected application paths.
Compensating Controls: Ensure that the Unisphere management interface is restricted to authorized internal networks and protected by a robust firewall to limit exposure to untrusted remote actors.
Exploitation status
Public Exploit Available: False
Analyst recommendation
Given the severity of the potential impact, administrators should prioritize applying the vendor-supplied security update to all affected instances. Failure to patch may expose the storage management environment to unauthorized file manipulation and potential system takeover.