Junglewise Threat Intelligence

CVE-2026-40633: Dell PowerScale OneFS sensitive information disclosure in log files

CVE-2026-40633 · Severity: high · CVSS 7.8 · Published 2026-07-15

Technologies: Dell PowerScale OneFS. Vendors: Dell.

Executive brief

Dell PowerScale OneFS, the operating system used for high-performance scale-out storage, is affected by a security vulnerability where sensitive information is improperly recorded in system log files. A user with low-level access to the system could read these logs to discover confidential data, potentially leading to further unauthorized access or data exposure. Dell has released security updates to address this issue and recommends upgrading to a remediated version.

Technical details

This vulnerability (CWE-532) exists in Dell PowerScale OneFS due to the improper insertion of sensitive information into system log files. A local attacker with low privileges (PR:L) can exploit this by accessing and reading these log files, leading to the disclosure of sensitive system or user information. The vulnerability affects multiple branches of OneFS, specifically versions 9.5.0.0 through 9.10.1.7 and 9.11.0.0 through 9.13.0.2. Dell has released patches in versions 9.10.1.8 and 9.13.1.0. As a mitigation, Dell recommends configuring non-root users to use the OneFS restricted shell.

Affected products

  • Dell PowerScale OneFS 9.5.0.0 through 9.10.1.7, 9.11.0.0 through 9.13.0.2

Timeline

  • 2026-06-30: advisory: Initial Dell advisory release
  • 2026-07-15: disclosed: NVD publication date

References

Related threats