Junglewise Threat Intelligence

CVE-2025-43936: Dell ObjectScale improper authentication

CVE-2025-43936 · Severity: high · CVSS 8.1 · Published 2026-09-16

Executive brief

Dell ObjectScale is an enterprise data storage platform that manages object storage across distributed infrastructure. An unauthenticated attacker with remote network access could bypass authentication controls, gaining unauthorized access to sensitive stored data and administrative functions without valid credentials.

Technical details

Dell ObjectScale prior to version 4.4.0.0 contains an improper authentication vulnerability that allows unauthenticated attackers to bypass authentication mechanisms. The vulnerability is remotely exploitable over the network with no authentication required and no user interaction needed. An attacker can achieve unauthorized access to the storage system, potentially enabling data theft, modification, or deletion. The fix is available in ObjectScale version 4.4.0.0 and later.

Affected products

  • Dell ObjectScale prior to 4.4.0.0

Timeline

  • 2026-09-16: disclosed

References

Related threats