Junglewise Threat Intelligence

CVE-2026-35066: Dell PowerFlex Manager improper access control

CVE-2026-35066 · Severity: high · CVSS 7.1 · Published 2026-06-17

Technologies: Dell PowerFlex Manager. Vendors: Dell.

Executive brief

Dell PowerFlex Manager, a tool used to manage and automate software-defined storage infrastructure, is vulnerable to an access control flaw. A user with low-level permissions can exploit this weakness over the network to disrupt operations, potentially causing a total denial of service for the management platform. This could prevent administrators from managing storage resources or responding to other infrastructure needs.

Technical details

Dell PowerFlex Manager is affected by an improper access control vulnerability (CWE-284). The flaw exists in the management software and can be triggered by a remote attacker who has successfully authenticated with low-level privileges. By exploiting this vulnerability, the attacker can cause a denial of service (DoS) condition, impacting the availability of the management interface. The vulnerability is addressed in PowerFlex versions 4.5.5.2 and 5.1.0.1 or later. The CVSS score of 7.1 reflects high availability impact despite requiring basic user credentials.

Affected products

  • Dell PowerFlex Manager Versions prior to 4.5.5.2; Versions prior to 5.1.0.1

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats