CVE-2026-70416
10.0Dell · ObjectScale
Dell ObjectScale versions prior to 4.4.0.0 are vulnerable to deserialization of untrusted data, allowing unauthenticated remote attackers to execute arbitrary code.
Executive summary
A critical deserialization vulnerability in Dell ObjectScale allows unauthenticated remote attackers to achieve full system compromise.
Vulnerability
This vulnerability, categorized as CWE-502, involves the improper deserialization of untrusted data. An unauthenticated attacker can leverage remote access to trigger this flaw, resulting in remote code execution with the highest level of privilege.
Business impact
The potential for remote code execution poses a catastrophic risk to business operations, as it grants attackers complete control over the affected storage infrastructure. This level of access could lead to total data exfiltration, permanent loss of service, or the use of the system as a pivot point for further lateral movement within the network. Given the CVSS score of 10.0, this issue must be treated as a top priority for immediate remediation.
Remediation
Immediate Action: Administrators must update Dell ObjectScale to version 4.4.0.0 or later immediately to eliminate the deserialization vulnerability.
Proactive Monitoring: Security teams should monitor network traffic for suspicious payloads destined for ObjectScale endpoints and scrutinize system logs for unexpected process execution.
Compensating Controls: Deploying a Web Application Firewall (WAF) with strict input validation rules may help filter malicious serialized objects, though this is a temporary measure and not a substitute for patching.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Due to the critical severity and the potential for total system compromise, organizations should prioritize the deployment of the vendor-supplied patch. Ensure that all affected ObjectScale instances are identified and updated to version 4.4.0.0 or later without delay to mitigate the risk of exploitation.
More Dell CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section