Junglewise Threat Intelligence

CVE-2026-46460: Dell PowerScale OneFS incorrect authorization in system logs

CVE-2026-46460 · Severity: low · CVSS 3.5 · Published 2026-09-09

Technologies: Dell PowerScale OneFS. Vendors: Dell.

Executive brief

Dell PowerScale OneFS is a storage operating system used in enterprise data centers. A low-privileged attacker with network access can bypass authorization controls and modify system logs, potentially hiding unauthorized activities or tampering with audit records critical for compliance and incident investigation.

Technical details

This is an incorrect authorization vulnerability in Dell PowerScale OneFS affecting versions 9.5.0.0 through 9.7.1.15, 9.8.0.0 through 9.13.1.0, and versions prior to 9.15.0.0. A low-privileged adjacent network attacker can exploit weak authorization checks to achieve unauthorized modification of system logs. The vulnerability requires the attacker to already have low-privilege credentials on an adjacent network. Patches are available: version 9.7.1.16 or later for the 9.5–9.7 branch and version 9.13.1.1 or later for the 9.11–9.13 branch.

Affected products

  • Dell PowerScale OneFS 9.5.0.0 through 9.7.1.15, 9.8.0.0 through 9.13.1.0, prior to 9.15.0.0

Timeline

  • 2026-09-09: disclosed
  • 2026-09-09: patched: Version 9.7.1.16 or later for 9.5–9.7 branch; version 9.13.1.1 or later for 9.11–9.13 branch

References

Related threats