Junglewise Threat Intelligence

CVE-2026-32804: Dell PowerFlex Manager improper authentication

CVE-2026-32804 · Severity: high · CVSS 8.1 · Published 2026-06-17

Technologies: Dell PowerFlex Manager. Vendors: Dell.

Executive brief

Dell PowerFlex Manager, a tool used to manage and automate software-defined storage infrastructure, contains a security flaw in how it verifies user identity. An attacker located on the same local network could bypass security checks to gain unauthorized access to the system. This could allow an attacker to modify system configurations or disrupt storage operations, potentially impacting data availability and integrity.

Technical details

An improper authentication vulnerability (CWE-287) exists in Dell PowerFlex Manager. The flaw allows an unauthenticated attacker with adjacent network access (on the same local subnet or broadcast domain) to bypass authentication mechanisms. Successful exploitation leads to unauthorized access with the ability to perform high-integrity modifications or cause service disruptions. The vulnerability is addressed in PowerFlex versions 4.5.5.2 and 5.1.0.1 or later.

Affected products

  • Dell PowerFlex Manager Versions prior to 4.5.5.2, versions prior to 5.1.0.1

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats