Executive brief
Dell Elastic Cloud Storage and ObjectScale, which provide enterprise-grade cloud storage solutions, are vulnerable to a flaw where sensitive information is recorded in system logs. A user with low-level access to the system could read these logs to discover secrets or credentials. This could allow an attacker to escalate their privileges and gain full control over the storage environment, potentially leading to data theft or service disruption.
Technical details
An 'Insertion of Sensitive Information into Log File' vulnerability (CWE-532) exists in Dell Elastic Cloud Storage (ECS) and ObjectScale. The flaw occurs when the software writes sensitive secrets or credentials into plain-text log files accessible to local users. An attacker with low-privileged local access can read these logs to extract credentials, subsequently using them to authenticate as a higher-privileged user or compromise the entire system. The vulnerability is remediated in ECS version 4.2.0.1 and ObjectScale versions 4.1.0.3 and 4.2.0.1.
Affected products
- Dell Elastic Cloud Storage (ECS) 3.8.1.0 through 3.8.1.7
- Dell ObjectScale Prior to 4.1.0.3, 4.2.0.0
Timeline
- 2026-04-06: advisory: Initial release of DSA-2026-143
- 2026-04-08: disclosed: CVE published to NVD
- 2026-05-07: other: Revised affected versions in vendor advisory