CVE-2026-58566
8.8Dell · PowerStore
A vulnerability in Dell PowerStore allows a low privileged, remote attacker to perform an incorrect authorization, leading to an elevation of privileges.
Executive summary
A high-severity authorization flaw in Dell PowerStore allows authenticated attackers to elevate their privileges, potentially gaining full control over affected storage systems.
Vulnerability
This vulnerability is an incorrect authorization flaw (CWE-863) that occurs when the system fails to properly validate the permission level of an authenticated user. A low privileged remote attacker can exploit this to perform unauthorized actions and escalate their privileges within the appliance.
Business impact
Successful exploitation of this vulnerability allows an attacker to gain elevated privileges, which could result in unauthorized access to sensitive data, modification of storage configurations, or total system compromise. Given the CVSS score of 8.8, this represents a significant risk to the integrity and availability of critical storage infrastructure.
Remediation
Immediate Action: Update all affected Dell PowerStore appliances to version 4.1.0.6-2771237 or later as specified in the Dell Security Advisory DSA-2026-330.
Proactive Monitoring: Review system audit logs for unusual administrative activity or unauthorized attempts to access restricted management functions by standard users.
Compensating Controls: Restrict network access to the PowerStore management interface to known, trusted administrative subnets and implement multi-factor authentication where supported.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations utilizing Dell PowerStore should prioritize the application of the vendor-supplied security update. Given the severity of the potential impact, administrators should schedule maintenance windows immediately to ensure the firmware is brought to the remediated version, thereby closing the privilege escalation vector.