Junglewise Threat Intelligence

CVE-2026-35157: Dell ECS and ObjectScale CSV injection in UI

CVE-2026-35157 · Severity: medium · CVSS 5.8 · Published 2026-05-11

Technologies: Dell ObjectScale, Dell ECS. Vendors: Dell.

Executive brief

Dell ECS and ObjectScale, which are enterprise storage solutions, are vulnerable to a security flaw in their management interface. An attacker could trick a user into downloading and opening a specially crafted file from the system, which could then execute malicious commands on the user's computer. This could lead to unauthorized access or the compromise of the user's workstation.

Technical details

A CSV injection vulnerability (CWE-1236) exists in the UI of Dell ECS (3.8.1.0-3.8.1.7) and Dell ObjectScale (prior to 4.3.0.0). The application fails to properly neutralize formula elements (such as =, +, -, or @) when generating CSV files. An unauthenticated remote attacker can exploit this by injecting malicious formulas into fields that are later exported to a CSV file. When a victim downloads and opens this file in a spreadsheet application like Microsoft Excel, the formula may execute, leading to remote code execution on the victim's machine. The attack requires user interaction and has a high complexity due to the reliance on the victim's spreadsheet software configuration.

Affected products

  • Dell ECS 3.8.1.0 - 3.8.1.7
  • Dell ObjectScale Prior to 4.3.0.0

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: advisory

References

Related threats