CVE-2026-26360
8.1Dell · Unisphere for PowerMax
Dell Unisphere for PowerMax contains an external control of file name or path vulnerability that allows low privileged remote attackers to delete arbitrary files.
Executive summary
A path traversal vulnerability in Dell Unisphere for PowerMax allows low privileged remote attackers to delete critical system files, potentially causing significant service disruption.
Vulnerability
This vulnerability is classified as an External Control of File Name or Path (CWE-73). A remote attacker with low-level privileges can manipulate file paths to delete arbitrary files on the underlying host.
Business impact
The ability to delete arbitrary files on a storage management system poses a severe risk to data integrity and system availability. Given the CVSS score of 8.1, this is a High severity issue that could lead to complete loss of management functionality or system crashes. Organizations relying on PowerMax for enterprise storage should prioritize this update to prevent potential service outages.
Remediation
Immediate Action: Upgrade to Dell Unisphere for PowerMax version 10.3.0.1 or later as specified in the vendor security advisory.
Proactive Monitoring: Review system access logs for unusual file deletion commands or suspicious activity originating from low privileged accounts.
Compensating Controls: Ensure strict network segmentation for management interfaces to limit the exposure of the Unisphere console to unauthorized or untrusted network segments.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
This vulnerability represents a significant risk to the availability of storage management infrastructure. Administrators must verify their current version of Unisphere for PowerMax and apply the 10.3.0.1 update immediately to eliminate the threat of arbitrary file deletion. Failure to patch may leave systems susceptible to malicious file removal that could result in extended downtime.