Junglewise Threat Intelligence

CVE-2026-58571: Dell PowerStore OS command injection with privilege escalation

CVE-2026-58571 · Severity: high · CVSS 8.8 · Published 2026-09-01

Technologies: Dell PowerStore. Vendors: Dell.

Executive brief

Dell PowerStore is a storage management appliance used by enterprises to manage data infrastructure. An authenticated user with limited administrative privileges can inject arbitrary operating system commands that execute with root-level privileges, potentially allowing complete system compromise and data access or destruction.

Technical details

CVE-2026-58571 is an OS command injection vulnerability in Dell PowerStore that permits authenticated users with limited privileges to execute arbitrary system commands with root privileges. The vulnerability requires local attack vector (AV:L) and user authentication, but no additional interaction is needed. An attacker who has obtained valid credentials for a standard user account can inject shell metacharacters or commands into a vulnerable input field or API parameter, bypassing input validation and resulting in full system compromise. Dell has issued a security update (DSA-2026-330) to address this and multiple related privilege escalation and authentication bypass vulnerabilities in the PowerStore family.

Affected products

  • Dell PowerStore <UNKNOWN>

Timeline

  • 2026-09-01: disclosed

References

Related threats