Junglewise Threat Intelligence

CVE-2026-56690: Dell PowerFlex Manager SQL injection

CVE-2026-56690 · Severity: high · CVSS 8.5 · Published 2026-07-10

Technologies: Dell PowerFlex Manager. Vendors: Dell.

Executive brief

Dell PowerFlex Manager, a tool used to manage and automate software-defined storage infrastructure, contains a security vulnerability that could allow an attacker to access sensitive information. By exploiting a flaw in how the system handles database queries, a user with low-level access could gain unauthorized access to data they are not permitted to see. This could lead to the exposure of internal system details or customer information, potentially compromising the integrity of the storage management environment.

Technical details

Dell PowerFlex Manager versions prior to 5.1.0.1 and 4.5.5.2 are vulnerable to SQL injection (CWE-89) due to improper neutralization of special elements used in SQL commands. A remote attacker with low-level privileges can exploit this vulnerability without user interaction. Successful exploitation can lead to unauthorized access, information disclosure, and information exposure. The vulnerability is characterized by a CVSS 3.1 score of 8.5, notably featuring a scope change (S:C), indicating the impact may extend beyond the PowerFlex Manager application itself. Dell has released security updates to address this issue.

Affected products

  • Dell PowerFlex Manager prior to 5.1.0.1, prior to 4.5.5.2

Timeline

  • 2026-07-10: disclosed
  • 2026-07-10: advisory

References

Related threats