Executive brief
Dell ECS and ObjectScale storage solutions contain a security flaw where fixed, pre-programmed login credentials are used. An attacker could use these credentials to gain unauthorized access to the system's underlying file system. This could allow them to view, modify, or delete sensitive stored data, potentially leading to a total compromise of the storage environment.
Technical details
Dell ECS (versions 3.8.1.0 through 3.8.1.7) and Dell ObjectScale (prior to 4.3.0.0) utilize hard-coded credentials (CWE-798). While the advisory text mentions 'local access' in the description, the provided CVSS 3.1 vector (AV:N) indicates the vulnerability is network-exploitable. An unauthenticated attacker can leverage these static credentials to gain unauthorized access to the underlying operating system's filesystem. This can result in full compromise of data confidentiality, integrity, and availability. Dell has released updates to address this issue in ECS and ObjectScale 4.3.0.0.
Affected products
- Dell ECS 3.8.1.0 - 3.8.1.7
- Dell ObjectScale Prior to 4.3.0.0
Timeline
- 2026-05-11: advisory: Initial publication of DSA-2026-019 and CVE-2026-40636