CVE-2026-67261

Dell · Virtual Storage Integrator for VMware vSphere Client

An OS command injection vulnerability exists in the Dell Virtual Storage Integrator for VMware vSphere Client, allowing unauthenticated remote attackers to execute arbitrary code as root.

Executive summary

A critical OS command injection flaw in Dell Virtual Storage Integrator allows unauthenticated remote attackers to execute arbitrary commands with root privileges, leading to full system compromise.

Vulnerability

The vulnerability exists within the IAPI component, which fails to properly sanitize input, enabling OS command injection by an unauthenticated attacker.

Business impact

A successful exploit provides the attacker with root-level access to the underlying operating system. This leads to a complete compromise of the Virtual Storage Integrator deployment, potentially impacting the confidentiality, integrity, and availability of managed storage environments and infrastructure.

Remediation

Immediate Action: Upgrade the Dell Virtual Storage Integrator for VMware vSphere Client to version 10.11.1.0 or later as recommended by the vendor.

Proactive Monitoring: Review system logs for suspicious process execution or unauthorized modifications to system files originating from the VSI component.

Compensating Controls: Use network-level access controls to restrict access to the VSI management interface to authorized administrative IP addresses only.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Due to the critical nature of remote code execution with root privileges, organizations should treat this update as an emergency deployment. Immediate patching is necessary to prevent total system takeover.