Executive brief
Dell SmartFabric Manager is a network fabric management tool used to administer data center infrastructure. A low-privileged attacker with network access can exploit improper permission handling to bypass authorization controls and access sensitive information, potentially compromising the confidentiality of system configuration and operational data.
Technical details
The vulnerability is a privilege escalation / authorization bypass due to improper handling of insufficient permissions or privileges in Dell SmartFabric Manager versions prior to 2.2.1. An attacker with low-level privileges and remote network access can exploit this flaw to circumvent access controls. The attack requires user interaction (UI:R) but no elevated privileges to initiate. Successful exploitation results in unauthorized disclosure of sensitive information. The fix is available in version 2.2.1 and later.
Affected products
- Dell SmartFabric Manager prior to 2.2.1
Timeline
- 2026-09-17: disclosed