Junglewise Threat Intelligence

CVE-2026-58575: Dell PowerStore authentication bypass by spoofing

CVE-2026-58575 · Severity: high · CVSS 8.8 · Published 2026-09-01

Technologies: Dell PowerStore. Vendors: Dell.

Executive brief

Dell PowerStore is a storage appliance used by enterprises to manage and protect critical data. An authenticated attacker with low-level access can exploit a spoofing vulnerability to escalate their privileges to full Administrator level, gaining complete control over the storage system and all data contained within it.

Technical details

CVE-2026-58575 is an authentication bypass vulnerability in Dell PowerStore that allows privilege escalation through spoofing techniques. The vulnerability requires an attacker to already be authenticated with low-level privileges on the affected system. By sending specially crafted requests that spoof authentication credentials or identities, an attacker can bypass authorization checks and elevate their access to Administrator level. The attack is network-accessible and requires no user interaction. Dell has released security updates addressing this vulnerability as part of DSA-2026-330.

Affected products

  • Dell PowerStore

Timeline

  • 2026-09-01: disclosed

References

Related threats