Junglewise Threat Intelligence

CVE-2026-79683: Dell PowerStore arbitrary file write via protection mechanism failure

CVE-2026-79683 · Severity: high · CVSS 8.8 · Published 2026-09-01

Technologies: Dell PowerStore. Vendors: Dell.

Executive brief

Dell PowerStore is a network storage appliance used by enterprises to store and manage critical data. An authenticated user with limited system privileges can write arbitrary files to any filesystem location, potentially overwriting system files, injecting malicious code, or causing system instability. This could lead to complete compromise of the storage system and exposure of all stored customer data.

Technical details

This is a protection mechanism failure vulnerability (CVE-2026-79683) affecting Dell PowerStore. An authenticated user with limited privileges can bypass filesystem access controls and write attacker-controlled content to arbitrary paths on the system. The vulnerability requires valid authentication credentials but no elevated privileges, and operates over the network. A successful exploit allows an attacker to modify critical system files, inject malicious code, or corrupt data, potentially leading to full system compromise. A security patch has been released by Dell (DSA-2026-330).

Affected products

  • Dell PowerStore

Timeline

  • 2026-09-01: disclosed

References

Related threats