Junglewise Threat Intelligence

CVE-2026-35160: Dell SmartFabric OS10 OS command injection

CVE-2026-35160 · Severity: medium · CVSS 5 · Published 2026-09-03

Executive brief

Dell SmartFabric OS10 is network switching software used in enterprise data centers. A high-privileged attacker with remote network access could inject arbitrary operating system commands through improper input validation, potentially executing code with system privileges and compromising the integrity of network infrastructure.

Technical details

The vulnerability is an OS command injection (CWE-78) in Dell SmartFabric OS10 prior to version 10.5.6.14, caused by improper neutralization of special elements in command construction. The flaw requires a high-privilege attacker with network-accessible remote access; no user interaction is needed. An attacker can inject malicious OS commands leading to arbitrary command execution on the affected device. A patch is available in version 10.5.6.14 and later.

Affected products

  • Dell SmartFabric OS10 prior to 10.5.6.14

Timeline

  • 2026-09-03: disclosed

References

Related threats