CVE-2026-79682

8.8

Dell · PowerStore

Dell PowerStore appliances are vulnerable to command injection, allowing an authenticated local user with limited privileges to execute arbitrary commands with root-level access.

Executive summary

A command injection vulnerability in Dell PowerStore appliances permits an authenticated attacker to escalate privileges to root, posing a severe risk of total system compromise.

Vulnerability

The vulnerability is categorized as CWE-77, Improper Neutralization of Special Elements used in a Command. An attacker who has already gained limited user access to the appliance can leverage this flaw to bypass security restrictions and execute arbitrary commands with root privileges.

Business impact

The potential for root-level command execution represents a critical threat to data integrity, confidentiality, and availability. With a CVSS score of 8.8, this vulnerability allows an attacker to gain full control over the storage appliance, potentially leading to unauthorized data exfiltration, permanent data loss, or total service disruption.

Remediation

Immediate Action: Update all affected Dell PowerStore appliances to version 4.1.0.6-2771237 or later as specified in the official vendor security advisory.

Proactive Monitoring: Review system access logs for unusual command execution patterns or privilege escalation attempts by existing user accounts.

Compensating Controls: Strictly enforce the principle of least privilege for all user accounts on the appliance and ensure that management interfaces are isolated from unauthorized network segments.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the severity of potential root-level compromise, administrators should prioritize the deployment of the vendor-supplied patch. Organizations should audit all current user accounts on their PowerStore appliances to ensure that only necessary personnel maintain access, thereby minimizing the attack surface for this privilege escalation flaw.

More Dell CVEs

Sources