Junglewise Threat Intelligence

CVE-2026-58566: Dell PowerStore incorrect authorization leading to privilege escalation

CVE-2026-58566 · Severity: high · CVSS 8.8 · Published 2026-09-01

Executive brief

Dell PowerStore is a enterprise storage appliance used to manage and protect critical business data. A low-privileged attacker with network access to the management interface could exploit an authorization flaw to invoke administrator-only operations and gain full control over the storage system, potentially leading to unauthorized data access, modification, or deletion.

Technical details

This vulnerability is an incorrect authorization flaw in Dell PowerStore that allows authenticated users with low privileges to invoke administrator-only operations without proper authorization checks. The attack vector is network-based and requires prior authentication but no additional user interaction. By exploiting this weakness, an attacker can escalate their privileges from a low-privilege account to administrative level, gaining full control over the storage appliance. A security patch is available through Dell's security advisory DSA-2026-330.

Affected products

  • Dell PowerStore

Timeline

  • 2026-09-01: disclosed

References

Related threats