Junglewise Threat Intelligence

CVE-2026-40635: Dell PowerScale OneFS insecure temporary file vulnerability

CVE-2026-40635 · Severity: medium · CVSS 5.4 · Published 2026-09-09

Technologies: Dell PowerScale OneFS. Vendors: Dell.

Executive brief

Dell PowerScale OneFS is a unified file storage and data management system used by enterprises to handle large-scale data operations. CVE-2026-40635 is an insecure temporary file vulnerability that allows a low-privilege attacker with network access to cause service denial and tamper with stored information, potentially disrupting business operations and compromising data integrity.

Technical details

CVE-2026-40635 is an insecure temporary file vulnerability in Dell PowerScale OneFS versions 9.12.0.0 through 9.13.1.0. The vulnerability can be exploited by a low-privileged remote attacker over the network without user interaction, requiring only valid credentials (PR:L). Exploitation leads to denial of service (availability impact) and information tampering (integrity impact). Patches are available in version 9.13.1.1 or later according to the remediation guidance.

Affected products

  • Dell PowerScale OneFS 9.12.0.0 through 9.13.1.0

Timeline

  • 2026-09-09: disclosed
  • 2026-09-09: patched: Version 9.13.1.1 or later

References

Related threats