Junglewise Threat Intelligence

CVE-2026-35162: Dell PowerFlex Manager improper access control denial of service

CVE-2026-35162 · Severity: medium · CVSS 4.3 · Published 2026-06-17

Technologies: Dell PowerFlex Manager. Vendors: Dell.

Executive brief

Dell PowerFlex Manager is a management tool used to automate and orchestrate software-defined storage environments. A security flaw in this software allows a user with low-level access to disrupt the system's availability. This could lead to a denial-of-service condition, preventing administrators from managing their storage infrastructure.

Technical details

Dell PowerFlex Manager is vulnerable to improper access control (CWE-284). A remote attacker with low-level privileges can exploit this flaw to trigger a denial-of-service (DoS) condition. The vulnerability exists in versions prior to 4.5.5.2 and 5.1.0.1. Exploitation does not require user interaction or high-level administrative rights, though it does require network access and valid low-privileged credentials. Dell has released security updates to address this issue in PowerFlex versions 4.5.5.2 and 5.1.0.1 or later.

Affected products

  • Dell PowerFlex Manager Versions prior to 4.5.5.2, versions prior to 5.1.0.1

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats