Executive brief
Dell ECS and ObjectScale are enterprise storage solutions used to manage large-scale data across different geographic locations. A security flaw in the data replication feature could allow an unauthorized person to bypass security checks and access data while it is being moved between systems. This could lead to the exposure of sensitive information during transit.
Technical details
An authentication bypass vulnerability (CWE-302) exists in the Geo replication feature of Dell ECS and ObjectScale. The flaw is rooted in 'assumed-immutable data,' where the system incorrectly trusts certain data elements that should be verified. An unauthenticated remote attacker can exploit this vulnerability to gain unauthorized access to data as it is replicated across geographic sites. The attack requires a high complexity (AC:H), likely involving specific timing or network positioning to intercept or manipulate the replication stream. Dell has released updates to address this issue in ObjectScale version 4.3.0.0 and relevant ECS patches.
Affected products
- Dell ECS 3.8.1.0 - 3.8.1.7
- Dell ObjectScale Prior to 4.3.0.0
Timeline
- 2026-05-11: advisory: Initial publication of DSA-2026-019 and CVE-2025-43992