CVE-2026-58571

8.8

Dell · PowerStore

Dell PowerStore appliances contain an OS command injection vulnerability allowing authenticated users with limited privileges to execute arbitrary commands with root-level access.

Executive summary

A high-severity OS command injection vulnerability in Dell PowerStore allows authenticated users to escalate privileges to root, posing a critical risk to storage infrastructure integrity.

Vulnerability

This flaw is an OS command injection (CWE-78) vulnerability triggered by improper neutralization of special elements in system commands. An attacker must possess limited authenticated access to the system to exploit this vulnerability and gain root privileges.

Business impact

The vulnerability carries a CVSS score of 8.8, reflecting the significant risk of full system compromise. Because the exploit grants root-level control, unauthorized parties could potentially access sensitive stored data, modify system configurations, or disrupt critical storage services, leading to severe operational downtime and data integrity loss.

Remediation

Immediate Action: Update all affected Dell PowerStore appliances to version 4.1.0.6-2771237 or later as detailed in the vendor security advisory.

Proactive Monitoring: Review system access logs for unusual command execution patterns or privilege escalation attempts by standard user accounts.

Compensating Controls: Restrict administrative access to the management interface to trusted personnel only, and employ network segmentation to limit the exposure of the storage appliance to internal networks.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the severity of potential root-level compromise, organizations should prioritize the application of the vendor-provided patch. Administrators must ensure that all PowerStore clusters are updated to the specified version to remediate the command injection flaw and prevent unauthorized privilege escalation.

More Dell CVEs

Sources