Junglewise Threat Intelligence

CVE-2026-28261: Dell ECS and ObjectScale sensitive information disclosure in logs

CVE-2026-28261 · Severity: high · CVSS 7.8 · Published 2026-04-08

Technologies: Dell ObjectScale, Dell Elastic Cloud Storage. Vendors: Dell.

Executive brief

Dell Elastic Cloud Storage and ObjectScale, which provide enterprise-grade cloud storage solutions, are vulnerable to a flaw where sensitive information is recorded in system logs. A user with low-level access to the system could read these logs to discover secrets or credentials. This could allow an attacker to escalate their privileges and gain full control over the storage environment, potentially leading to data theft or service disruption.

Technical details

An 'Insertion of Sensitive Information into Log File' vulnerability (CWE-532) exists in Dell Elastic Cloud Storage (ECS) and ObjectScale. The flaw occurs when the software writes sensitive secrets or credentials into plain-text log files accessible to local users. An attacker with low-privileged local access can read these logs to extract credentials, subsequently using them to authenticate as a higher-privileged user or compromise the entire system. The vulnerability is remediated in ECS version 4.2.0.1 and ObjectScale versions 4.1.0.3 and 4.2.0.1.

Affected products

  • Dell Elastic Cloud Storage (ECS) 3.8.1.0 through 3.8.1.7
  • Dell ObjectScale Prior to 4.1.0.3, 4.2.0.0

Timeline

  • 2026-04-06: advisory: Initial release of DSA-2026-143
  • 2026-04-08: disclosed: CVE published to NVD
  • 2026-05-07: other: Revised affected versions in vendor advisory

References

Related threats