Executive brief
Dell PowerStore is an enterprise storage system used by organizations to manage and protect critical data. An authenticated user with limited administrative privileges can exploit a flaw in how the system handles functionality loaded from untrusted sources, allowing them to execute code with root-level access and potentially compromise the entire storage platform and all data it contains.
Technical details
The vulnerability is a classic "Inclusion of Functionality from Untrusted Control Sphere" (CWE-829) flaw in Dell PowerStore. An authenticated attacker with limited privileges can supply or influence code or functionality that the system loads and executes with root-level permissions. The attack vector is local with low attack complexity; the attacker requires valid authentication credentials but no elevated privileges. Successful exploitation allows arbitrary code execution with root privileges, fully compromising system integrity and confidentiality. Patches are available as documented in DSA-2026-330.
Affected products
- Dell PowerStore
Timeline
- 2026-09-01: disclosed