CVE-2026-58574
9.8Dell · PowerStore T Series
Dell PowerStore appliances contain a missing authentication vulnerability that allows unauthenticated attackers to read sensitive internal system files and potentially gain full administrative access.
Executive summary
An unauthenticated, critical vulnerability in Dell PowerStore T series appliances exposes sensitive filesystem data and risks full administrative compromise of the storage array.
Vulnerability
This is a Missing Authentication for Critical Function vulnerability (CWE-306) affecting the management interface. An unauthenticated attacker with network access can bypass security controls to read internal filesystem data, including credentials that facilitate full administrative takeover.
Business impact
The exploitation of this vulnerability poses a severe risk to data confidentiality, integrity, and availability. With a CVSS score of 9.8, this flaw allows unauthorized actors to bypass authentication to extract sensitive system information, leading to potential full administrative control over the storage array, which may result in data exfiltration or permanent destruction of enterprise storage assets.
Remediation
Immediate Action: Update all affected Dell PowerStore T series appliances to firmware version 4.1.0.6-2771237 or later as specified in the official Dell security advisory DSA-2026-330.
Proactive Monitoring: Monitor management interface access logs for unauthorized connection attempts or unusual patterns of file access requests.
Compensating Controls: Restrict network access to the PowerStore management interface to authorized administrative subnets only via firewall rules or VPN controls until the patch is applied.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical nature of this vulnerability and the potential for complete administrative compromise, immediate patching is required. Organizations should prioritize the update of all reachable PowerStore management interfaces to the latest vendor-provided firmware to eliminate this high-risk attack vector.