CVE-2026-59910

7.8

Dell · ObjectScale

Dell ObjectScale is vulnerable to OS command injection, allowing a local authenticated attacker to execute arbitrary system commands.

Executive summary

A high-severity OS command injection vulnerability in Dell ObjectScale could allow a local authenticated attacker to execute arbitrary commands with elevated privileges.

Vulnerability

This vulnerability, identified as CWE-78, involves the improper neutralization of special elements used in an OS command. The flaw requires the attacker to possess low-level local authentication to successfully trigger the injection vector.

Business impact

Successful exploitation of this vulnerability could lead to a total compromise of the affected system. An attacker could gain unauthorized control, potentially leading to data exfiltration, service disruption, or further lateral movement within the network. Given the CVSS score of 7.8, this represents a significant risk to organizational integrity and availability.

Remediation

Immediate Action: Upgrade Dell ObjectScale to version 4.3.0.1 or later as specified in the vendor security advisory.

Proactive Monitoring: Review system logs for unusual command execution patterns or unauthorized process spawning that may indicate exploitation attempts.

Compensating Controls: Ensure that access to the local environment is strictly restricted to authorized personnel only, following the principle of least privilege.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The high severity of this OS command injection flaw necessitates immediate attention. Organizations should prioritize updating to version 4.3.0.1 to eliminate the risk of unauthorized system command execution.

More Dell CVEs