CVE-2026-28261
7.8Dell · Elastic Cloud Storage, ObjectScale
Dell Elastic Cloud Storage and ObjectScale contain an insertion of sensitive information into log files, allowing low-privileged local attackers to expose secrets and potentially escalate privileges.
Executive summary
A critical information disclosure vulnerability in Dell Elastic Cloud Storage and ObjectScale permits local attackers to harvest sensitive secrets from log files, posing a high risk of unauthorized access.
Vulnerability
The software suffers from CWE-532, where sensitive information is improperly written to log files. A locally authenticated user with low privileges can access these logs to retrieve credentials or secrets, which may then be used to gain further unauthorized access to the system.
Business impact
The exploitation of this vulnerability could lead to a complete compromise of the confidentiality, integrity, and availability of the affected storage systems. Given the CVSS score of 7.8, this flaw represents a significant risk to data security and administrative control, as exposed secrets often provide a pathway for lateral movement or full system takeover.
Remediation
Immediate Action: Update Dell Elastic Cloud Storage to version 4.2.0.1 or later, and update Dell ObjectScale to version 4.1.0.3 or 4.2.0.1 as specified in the vendor security advisory.
Proactive Monitoring: Audit system logs for unauthorized access attempts and implement strict file permission controls on log directories to restrict visibility to authorized administrative accounts only.
Compensating Controls: If patching is delayed, restrict local system access to only essential personnel and monitor for any unusual process activity that may indicate an attempt to scrape sensitive data from filesystem logs.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations should prioritize the application of the vendor-provided updates to remediate this sensitive information disclosure. Because the vulnerability allows for the extraction of credentials that could facilitate further attacks, patching should be performed during the next maintenance window to ensure the protection of stored data and system integrity.