Junglewise Threat Intelligence

CVE-2026-26950: Dell SmartFabric Manager insufficient data authenticity verification

CVE-2026-26950 · Severity: high · CVSS 8.1 · Published 2026-09-17

Vendors: Dell.

Executive brief

Dell SmartFabric Manager is a fabric management platform used in enterprise data center environments to configure and monitor network infrastructure. CVE-2026-26950 allows a low-privileged authenticated attacker to bypass data authenticity checks and escalate privileges to gain unauthorized access to system functions, potentially compromising the entire managed fabric infrastructure.

Technical details

The vulnerability is classified as Insufficient Verification of Data Authenticity in Dell SmartFabric Manager versions prior to 2.2.1. A low-privileged attacker with remote network access and valid credentials can exploit this flaw to bypass authentication and authorization controls, leading to elevation of privileges. The attack requires no user interaction (UI:N) and operates over the network (AV:N). This allows an attacker to gain high-impact unauthorized access to confidential data and modify system configuration. The patch is available in version 2.2.1 and later.

Affected products

  • Dell SmartFabric Manager prior to 2.2.1

Timeline

  • 2026-09-17: disclosed
  • 2026-09-17: patched: Version 2.2.1 or later

References

Related threats