Executive brief
Dell ObjectScale is an enterprise data storage and management platform used by organizations to store and manage large volumes of unstructured data. An unauthenticated attacker with network access could exploit a deserialization flaw to execute arbitrary code on affected systems, potentially compromising the entire storage infrastructure, exposing sensitive customer data, and disrupting critical business operations.
Technical details
The vulnerability is a deserialization of untrusted data flaw in Dell ObjectScale versions prior to 4.4.0.0. An unauthenticated attacker with remote network access can exploit this vulnerability without authentication, user interaction, or special privileges. The attacker can send specially crafted serialized data that, when deserialized by the affected component, allows arbitrary remote code execution with full system privileges. The vulnerability is patched in version 4.4.0.0 and later. The CVSS base score is 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H), indicating maximum severity.
Affected products
- Dell ObjectScale prior to 4.4.0.0
Timeline
- 2026-09-16: disclosed
- 2026-09-16: patched: Fixed in version 4.4.0.0