Executive brief
Dell PowerStore is a networked storage appliance used by enterprises to manage and store critical data. An authenticated user with basic access privileges can inject malicious commands that execute with administrative (root) permissions, allowing them to take full control of the storage system, access sensitive data, or disrupt business operations.
Technical details
CVE-2026-79682 is a command injection vulnerability in Dell PowerStore that allows an authenticated user with limited privileges to execute arbitrary commands with root privileges. The vulnerability exists in a component that processes user input without proper sanitization or validation of shell metacharacters. An attacker requires valid authentication credentials (low privilege level) and local or network access to the affected interface; no additional user interaction is required. Successful exploitation results in unauthenticated code execution with the highest system privileges, compromising the entire storage system. Dell has released a security update (DSA-2026-330) addressing this and multiple related vulnerabilities.
Affected products
- Dell PowerStore
Timeline
- 2026-09-01: disclosed