Junglewise Threat Intelligence

CVE-2026-76104: Dell ObjectScale incorrect permission assignment in OS

CVE-2026-76104 · Severity: medium · CVSS 5.5 · Published 2026-09-16

Executive brief

Dell ObjectScale is an enterprise storage platform used to manage large-scale object storage infrastructure. A vulnerability in its operating system allows a high-privileged attacker with network access to trigger a denial of service, disrupting storage availability and potentially impacting business operations dependent on continuous data access.

Technical details

CVE-2026-76104 is an incorrect permission assignment vulnerability in the Dell ObjectScale operating system that allows a high-privileged attacker with network access to cause a denial of service condition. The vulnerability stems from improper permissions on critical OS resources, enabling an authenticated high-privileged user to interfere with system integrity and availability. The attack requires high privilege level but no user interaction. An attacker can exploit this to degrade or disable storage service availability. The vulnerability is remediated in ObjectScale version 4.4.0.0 and later; Dell recommends immediate upgrade via service request.

Affected products

  • Dell ObjectScale prior to 4.4.0.0

Timeline

  • 2026-09-16: disclosed

References

Related threats