Junglewise Threat Intelligence

CVE-2026-70416: Dell ObjectScale deserialization of untrusted data vulnerability

CVE-2026-70416 · Severity: critical · CVSS 10 · Published 2026-09-16

Executive brief

Dell ObjectScale is an enterprise data storage and management platform used by organizations to store and manage large volumes of unstructured data. An unauthenticated attacker with network access could exploit a deserialization flaw to execute arbitrary code on affected systems, potentially compromising the entire storage infrastructure, exposing sensitive customer data, and disrupting critical business operations.

Technical details

The vulnerability is a deserialization of untrusted data flaw in Dell ObjectScale versions prior to 4.4.0.0. An unauthenticated attacker with remote network access can exploit this vulnerability without authentication, user interaction, or special privileges. The attacker can send specially crafted serialized data that, when deserialized by the affected component, allows arbitrary remote code execution with full system privileges. The vulnerability is patched in version 4.4.0.0 and later. The CVSS base score is 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H), indicating maximum severity.

Affected products

  • Dell ObjectScale prior to 4.4.0.0

Timeline

  • 2026-09-16: disclosed
  • 2026-09-16: patched: Fixed in version 4.4.0.0

References

Related threats