Executive brief
Dell PowerStore is a storage array management platform that controls enterprise data. An attacker on the network can access a critical management interface without credentials and read sensitive system information, including administrative credentials, giving them complete control of the storage system.
Technical details
This is a missing authentication vulnerability (CWE-306) in Dell PowerStore's restricted management interface. An unauthenticated attacker with network access can bypass authentication controls on a critical function to read internal system information from the appliance filesystem, including credentials that provide full administrative access. The attack requires network access to the management interface but no user interaction or authentication. Patches are available via Dell security advisory DSA-2026-330.
Affected products
- Dell PowerStore
Timeline
- 2026-08-31: disclosed