Executive brief
Dell PowerStore is an enterprise storage appliance used for data management across organizations. An authenticated user with basic permissions can exploit a flaw in authorization controls to invoke administrator-only functions, gaining full control over the storage system and potentially exposing or corrupting all stored data.
Technical details
CVE-2026-76111 is an incorrect authorization (CWE-863) vulnerability in Dell PowerStore. The vulnerability allows an authenticated attacker with low-privilege credentials to bypass authorization checks and invoke administrator-level operations via the management interface over the network. The attack requires valid credentials and network access to the management interface, but no user interaction. Successful exploitation results in privilege escalation, granting the attacker administrative control over the storage system and potentially leading to data exfiltration, modification, or deletion. A security update is available from Dell (DSA-2026-330).
Affected products
- Dell PowerStore <UNKNOWN>
Timeline
- 2026-09-01: disclosed