Executive brief
Dell Elastic Cloud Storage (ECS) and ObjectScale are enterprise storage platforms used to manage and store large volumes of data. A vulnerability in privilege management allows a high-privileged local attacker to escalate their privileges, potentially gaining complete control over the system and accessing or modifying sensitive data stored within.
Technical details
This vulnerability is an Improper Privilege Management issue affecting Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.4.0.0. The flaw allows a high-privileged attacker with local access to exploit improper privilege controls and escalate to higher privilege levels. The attack requires local system access and elevated privileges as a precondition. Successful exploitation results in privilege escalation, enabling the attacker to achieve high-impact compromise of confidentiality, integrity, and availability. A patch is available in version 4.4.0.0 or later for ObjectScale, and version 4.4.0.0 or later for ECS.
Affected products
- Dell Elastic Cloud Storage 3.8.1.0 through 3.8.1.7
- Dell ObjectScale prior to 4.4.0.0
Timeline
- 2026-09-16: disclosed