Executive brief
Dell PowerScale OneFS is the operating system used for high-performance scale-out storage solutions. A security flaw in how the system assigns permissions could allow a user with limited access to gain higher-level administrative privileges. This could lead to unauthorized changes to system settings or disruption of storage services.
Technical details
An incorrect privilege assignment vulnerability (CWE-266) exists in Dell PowerScale OneFS. The flaw is present in versions 9.5.0.0 through 9.10.1.6 and 9.11.0.0 through 9.13.0.1. A local attacker with low-level credentials can exploit this misconfiguration to gain elevated permissions on the storage cluster. Successful exploitation could allow the attacker to perform unauthorized administrative actions or impact system availability. Dell has released patches in versions 9.10.1.7 and 9.13.0.2 to address this issue.
Affected products
- Dell PowerScale OneFS 9.5.0.0 - 9.10.1.6, 9.11.0.0 - 9.13.0.1
Timeline
- 2026-04-06: advisory: Initial release of Dell Security Advisory DSA-2026-125
- 2026-04-08: disclosed: CVE-2026-27102 published