Executive brief
Dell ECS, a cloud storage platform, contains a security flaw in its identity management component. This vulnerability allows an unauthorized person to bypass certain access controls over the network. If exploited, an attacker could view sensitive data they are not permitted to see, potentially compromising confidential business information.
Technical details
An improper access control vulnerability (CWE-284) exists within the Identity and Access Management (IAM) module of Dell ECS. The flaw allows a remote, unauthenticated attacker to bypass authorization checks under certain conditions. By exploiting this, an attacker can gain unauthorized read access to data stored on the system. The vulnerability affects versions 3.5.x (prior to 3.5.1.7) and 3.6.x (prior to 3.6.2.4). While the attack vector is network-based and requires no privileges, the complexity is rated as high by the vendor.
Affected products
- Dell ECS (Elastic Cloud Storage) 3.5.x prior to 3.5.1.7, 3.6.x prior to 3.6.2.4
Timeline
- 2026-05-22: disclosed: Initial publication of the vulnerability advisory.