Junglewise Threat Intelligence

CVE-2026-58567: Dell PowerStore OS command injection

CVE-2026-58567 · Severity: high · CVSS 8.8 · Published 2026-09-01

Executive brief

Dell PowerStore is a storage appliance used to manage enterprise data and block storage. An authenticated user with low-level privileges could exploit a command injection flaw to execute arbitrary system commands with root-level privileges, potentially leading to full compromise of the storage system and all data stored on it.

Technical details

CVE-2026-58567 is an OS command injection vulnerability in Dell PowerStore that allows an authenticated attacker with limited (low) privileges to execute arbitrary operating system commands with root privileges. The vulnerability exists in a command-handling mechanism that fails to properly sanitize user input before passing it to system shell execution. The attack vector is local (requires authenticated access and likely local console or API access), and no user interaction is required once the attacker is authenticated. Successful exploitation grants the attacker complete control of the affected PowerStore system. A patch is expected to be available via Dell's DSA-2026-330 security update.

Affected products

  • Dell PowerStore

Timeline

  • 2026-09-01: disclosed
  • 2026-09-01: advisory: Dell DSA-2026-330 issued

References

Related threats