Junglewise Threat Intelligence

CVE-2026-58572: Dell PowerStore code injection via authenticated user

CVE-2026-58572 · Severity: high · CVSS 8.8 · Published 2026-09-01

Technologies: Dell PowerStore. Vendors: Dell.

Executive brief

Dell PowerStore is a storage array management appliance used by enterprises to manage data infrastructure. CVE-2026-58572 allows an authenticated user with limited privileges to execute arbitrary code with root-level privileges through a code injection flaw, potentially compromising the entire storage system and all data stored on it.

Technical details

The vulnerability is a code injection flaw (CWE-94) in Dell PowerStore that allows authenticated users with limited privileges to inject and execute arbitrary code. The attack requires valid authentication credentials and executes with root privileges, bypassing normal access controls. The attack vector is local with low complexity and low privilege requirements. An attacker can achieve full system compromise, including data exfiltration, modification, and denial of service. Patches are available via Dell's DSA-2026-330 security update.

Affected products

  • Dell PowerStore

Timeline

  • 2026-09-01: disclosed

References

Related threats