CVE-2026-58572

8.8

Dell · PowerStore T Series

Dell PowerStore appliances are vulnerable to code injection, allowing an authenticated low-privileged user to achieve arbitrary code execution with root privileges.

Executive summary

A critical code injection vulnerability in Dell PowerStore T series appliances allows authenticated attackers to gain full root-level control over the storage system.

Vulnerability

This is a code injection vulnerability (CWE-94) that allows an authenticated user with limited privileges to execute arbitrary code. The flaw enables privilege escalation to the root level, effectively compromising the entire storage appliance.

Business impact

The ability for a low-privileged user to gain root access represents a catastrophic security failure for storage infrastructure. Successful exploitation could lead to total data compromise, unauthorized modification of storage volumes, and complete system denial of service. With a CVSS score of 8.8, this vulnerability is categorized as High, reflecting the severe impact on confidentiality, integrity, and availability within the data center environment.

Remediation

Immediate Action: Update all affected Dell PowerStore T series appliances to version 4.1.0.6-2771237 or later as specified in the vendor security advisory DSA-2026-330.

Proactive Monitoring: Review administrative access logs for suspicious command execution or unexpected privilege escalation attempts.

Compensating Controls: Restrict administrative console access to trusted management networks and ensure that only authorized personnel have authenticated access to the appliance management interface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for complete system takeover, organizations must prioritize the application of the vendor-supplied patch. Administrators should verify their current firmware versions immediately and schedule maintenance windows to update any systems running versions prior to 4.1.0.6-2771237. Failure to remediate this vulnerability leaves critical storage infrastructure exposed to significant internal threats.

More Dell CVEs

Sources