CVE-2026-58574

9.8

Dell · PowerStore T Series

Dell PowerStore appliances contain a missing authentication vulnerability that allows unauthenticated attackers to read sensitive internal system files and potentially gain full administrative access.

Executive summary

An unauthenticated, critical vulnerability in Dell PowerStore T series appliances exposes sensitive filesystem data and risks full administrative compromise of the storage array.

Vulnerability

This is a Missing Authentication for Critical Function vulnerability (CWE-306) affecting the management interface. An unauthenticated attacker with network access can bypass security controls to read internal filesystem data, including credentials that facilitate full administrative takeover.

Business impact

The exploitation of this vulnerability poses a severe risk to data confidentiality, integrity, and availability. With a CVSS score of 9.8, this flaw allows unauthorized actors to bypass authentication to extract sensitive system information, leading to potential full administrative control over the storage array, which may result in data exfiltration or permanent destruction of enterprise storage assets.

Remediation

Immediate Action: Update all affected Dell PowerStore T series appliances to firmware version 4.1.0.6-2771237 or later as specified in the official Dell security advisory DSA-2026-330.

Proactive Monitoring: Monitor management interface access logs for unauthorized connection attempts or unusual patterns of file access requests.

Compensating Controls: Restrict network access to the PowerStore management interface to authorized administrative subnets only via firewall rules or VPN controls until the patch is applied.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical nature of this vulnerability and the potential for complete administrative compromise, immediate patching is required. Organizations should prioritize the update of all reachable PowerStore management interfaces to the latest vendor-provided firmware to eliminate this high-risk attack vector.

More Dell CVEs

Sources