Junglewise Threat Intelligence

CVE-2026-54470: Dell Unisphere for PowerMax XXE vulnerability

CVE-2026-54470 · Severity: medium · CVSS 5.3 · Published 2026-07-10

Technologies: Dell Unisphere For Powermax Virtual Appliance, Dell Unisphere for PowerMax. Vendors: Dell.

Executive brief

Dell Unisphere for PowerMax, a management interface for enterprise storage arrays, is vulnerable to a security flaw that could allow an attacker to access sensitive information. A user with low-level access to the system could exploit this vulnerability to gain unauthorized access to data or internal system details. This could potentially lead to further compromise of the storage management environment.

Technical details

Dell Unisphere for PowerMax contains an Improper Restriction of XML External Entity Reference (XXE) vulnerability (CWE-611). The vulnerability exists in the way the application processes XML input, failing to properly restrict references to external entities. A remote attacker with low-level privileges can exploit this by sending a specially crafted XML payload to the server. Successful exploitation could allow the attacker to read local files, conduct server-side request forgery (SSRF), or gain unauthorized access to sensitive data. The issue is addressed in versions 10.3.0.7 and 10.3.1.1 Patch 11360 or later.

Affected products

  • Dell Unisphere for PowerMax 10.3.0.5 and prior
  • Dell Unisphere for PowerMax Virtual Appliance 10.3.0.5 and prior

Timeline

  • 2026-07-10: advisory: Initial publication of DSA-2026-272 and NVD entry

References

Related threats