Junglewise Threat Intelligence

CVE-2026-70425: Dell PowerScale OneFS command injection privilege escalation

CVE-2026-70425 · Severity: medium · CVSS 6.7 · Published 2026-09-09

Technologies: Dell PowerScale OneFS. Vendors: Dell.

Executive brief

Dell PowerScale OneFS is a network-attached storage operating system used to manage enterprise data at scale. A command injection vulnerability allows an authenticated administrator with local access to escalate privileges to root, gaining complete control over the storage system and potentially exposing or destroying all data stored on it.

Technical details

CVE-2026-70425 is a command injection vulnerability in Dell PowerScale OneFS that allows an admin-privileged local attacker to execute arbitrary commands with elevated privileges. The vulnerability exists in versions 9.5.0.0 through 9.7.1.0, 9.8.0.0 through 9.10.1.0, and 9.11.0.0 through 9.14.0.1. An attacker with administrative credentials and local system access can inject shell commands that escalate to root privileges, compromising confidentiality, integrity, and availability of the system. The attack requires high privileges (admin role) and local access, limiting the immediate threat to insider threats or compromised admin accounts. Patches are available; affected customers should upgrade to patched versions.

Affected products

  • Dell PowerScale OneFS 9.5.0.0 through 9.7.1.0, 9.8.0.0 through 9.10.1.0, 9.11.0.0 through 9.14.0.1

Timeline

  • 2026-09-09: disclosed

References

Related threats