Junglewise Threat Intelligence

CVE-2026-40636: Dell ECS and ObjectScale hard-coded credentials

CVE-2026-40636 · Severity: critical · CVSS 9.8 · Published 2026-05-11

Executive brief

Dell ECS and ObjectScale storage solutions contain a security flaw where fixed, pre-programmed login credentials are used. An attacker could use these credentials to gain unauthorized access to the system's underlying file system. This could allow them to view, modify, or delete sensitive stored data, potentially leading to a total compromise of the storage environment.

Technical details

Dell ECS (versions 3.8.1.0 through 3.8.1.7) and Dell ObjectScale (prior to 4.3.0.0) utilize hard-coded credentials (CWE-798). While the advisory text mentions 'local access' in the description, the provided CVSS 3.1 vector (AV:N) indicates the vulnerability is network-exploitable. An unauthenticated attacker can leverage these static credentials to gain unauthorized access to the underlying operating system's filesystem. This can result in full compromise of data confidentiality, integrity, and availability. Dell has released updates to address this issue in ECS and ObjectScale 4.3.0.0.

Affected products

  • Dell ECS 3.8.1.0 - 3.8.1.7
  • Dell ObjectScale Prior to 4.3.0.0

Timeline

  • 2026-05-11: advisory: Initial publication of DSA-2026-019 and CVE-2026-40636

References

Related threats