Junglewise Threat Intelligence

CVE-2026-40638: Dell PowerScale InsightIQ privilege escalation via unnecessary privileges

CVE-2026-40638 · Severity: medium · CVSS 6.7 · Published 2026-05-12

Vendors: Dell.

Executive brief

Dell PowerScale InsightIQ is a performance monitoring and reporting tool for scale-out storage systems. A vulnerability in this software allows an attacker who already has high-level access to the local system to execute tasks with even higher privileges. This could lead to a complete takeover of the monitoring appliance and potential disruption of storage analytics.

Technical details

Dell PowerScale InsightIQ (versions 5.0.0 to 6.2.0) is vulnerable to an 'Execution with Unnecessary Privileges' (CWE-250) flaw. The vulnerability exists because certain components or processes run with higher privileges than required for their intended function. An attacker who has already obtained high-privileged local access to the InsightIQ system can exploit this misconfiguration to further elevate their privileges, potentially reaching root or administrative control over the underlying operating system. The issue is resolved in version 6.3.0 or later.

Affected products

  • Dell PowerScale InsightIQ 5.0.0 through 6.2.0

Timeline

  • 2026-05-11: advisory: Initial release of Dell Security Advisory DSA-2026-208
  • 2026-05-12: disclosed: NVD publication date

References

Related threats