Junglewise Threat Intelligence

CVE-2026-56688: Dell PowerFlex Manager OS command injection in OS Repository processing

CVE-2026-56688 · Severity: critical · CVSS 9.1 · Published 2026-07-10

Technologies: Dell PowerFlex Manager. Vendors: Dell.

Executive brief

Dell PowerFlex Manager is a tool used to manage and automate software-defined storage infrastructure. A security vulnerability in this tool allows a high-privileged user to execute unauthorized commands with the highest level of system permissions (root). If exploited, this could lead to a complete takeover of the management appliance and allow the attacker to move laterally into the connected storage infrastructure.

Technical details

An OS command injection vulnerability (CWE-78) exists in Dell PowerFlex Manager due to improper neutralization of special elements during OS Repository processing. A remote attacker with high privileges can exploit this flaw to execute arbitrary commands as root on the underlying operating system. The vulnerability is characterized by a CVSS 3.1 score of 9.1, reflecting its high impact and the potential for scope change (S:C), which could lead to lateral movement within the managed infrastructure. Dell has released patches in versions 5.1.0.1 and 4.5.5.2 to address this issue.

Affected products

  • Dell PowerFlex Manager Prior to 5.1.0.1, prior to 4.5.5.2

Timeline

  • 2026-07-10: advisory: Dell published the security update DSA-2026-066.
  • 2026-07-10: disclosed

References

Related threats