Executive brief
Dell PowerScale OneFS, the operating system for high-performance network-attached storage (NAS) systems, is affected by a privilege management vulnerability. An attacker who already possesses high-level administrative access to the local system could exploit this flaw to further elevate their permissions. This could allow an authorized user to bypass intended security restrictions and gain full control over the storage environment and its data.
Technical details
An improper privilege management vulnerability (CWE-269) exists in Dell PowerScale OneFS. The flaw is present in versions 9.5.0.0 through 9.10.1.7 and 9.11.0.0 through 9.13.0.2. A high-privileged attacker with local access can exploit this vulnerability to achieve a higher level of privilege than intended. The attack vector is local and requires no user interaction. Dell has released remediated versions 9.10.1.8 and 9.13.1.0 to address this issue. As a mitigation, Dell recommends configuring non-root users with the restricted shell for CLI access.
Affected products
- Dell PowerScale OneFS 9.5.0.0 through 9.10.1.7, 9.11.0.0 through 9.13.0.2
Timeline
- 2026-06-30: advisory: Initial release of Dell Security Advisory DSA-2026-261
- 2026-07-15: disclosed: NVD publication date