Executive brief
Dell PowerStore is a enterprise storage appliance used to manage and protect critical business data. A low-privileged attacker with network access to the management interface could exploit an authorization flaw to invoke administrator-only operations and gain full control over the storage system, potentially leading to unauthorized data access, modification, or deletion.
Technical details
This vulnerability is an incorrect authorization flaw in Dell PowerStore that allows authenticated users with low privileges to invoke administrator-only operations without proper authorization checks. The attack vector is network-based and requires prior authentication but no additional user interaction. By exploiting this weakness, an attacker can escalate their privileges from a low-privilege account to administrative level, gaining full control over the storage appliance. A security patch is available through Dell's security advisory DSA-2026-330.
Affected products
- Dell PowerStore
Timeline
- 2026-09-01: disclosed