Junglewise Threat Intelligence

CVE-2026-35065: Dell PowerFlex Manager missing authentication for critical function

CVE-2026-35065 · Severity: high · CVSS 8.8 · Published 2026-06-17

Technologies: Dell PowerFlex Manager. Vendors: Dell.

Executive brief

Dell PowerFlex Manager, a tool used to manage and automate software-defined storage infrastructure, contains a security flaw where critical functions do not require authentication. An attacker on the same local network could exploit this to gain unauthorized access, steal sensitive data, or disrupt storage operations. This could lead to a total compromise of the management system and the underlying storage environment.

Technical details

Dell PowerFlex Manager is vulnerable to a Missing Authentication for Critical Function (CWE-306). The flaw exists because certain sensitive operations within the management interface do not properly verify the identity of the requester. An unauthenticated attacker with adjacent network access (on the same local network or subnet) can exploit this to perform administrative actions. Successful exploitation can lead to remote code execution (RCE), denial of service (DoS), script injection, and full unauthorized access to the system. Dell has released security updates in versions 4.5.5.2 and 5.1.0.1 to address this issue.

Affected products

  • Dell PowerFlex Manager Versions prior to 4.5.5.2; Versions prior to 5.1.0.1

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats