Junglewise Threat Intelligence

CVE-2026-79684: Dell PowerStore privilege escalation via protection mechanism bypass

CVE-2026-79684 · Severity: high · CVSS 8.8 · Published 2026-09-01

Technologies: Dell PowerStore. Vendors: Dell.

Executive brief

Dell PowerStore is an enterprise storage array used to store and manage critical business data. CVE-2026-79684 allows an authenticated user with basic access to bypass security controls and gain administrative privileges, potentially enabling full control over the storage system, data theft, or denial of service. An attacker with even minimal legitimate access could escalate to administrative access without requiring additional credentials.

Technical details

CVE-2026-79684 is a Protection Mechanism Failure vulnerability in Dell PowerStore that allows authenticated users with limited privileges to bypass access restrictions and escalate to elevated privileges. The vulnerability is accessible over the network without user interaction, requiring only valid authentication credentials at a limited privilege level (CVSS vector: AV:N/AC:L/PR:L/UI:N). An authenticated attacker can exploit this flaw to gain administrative access and perform unauthorized operations including data manipulation, code execution, or system compromise. A patch or security update from Dell is expected to address this and related vulnerabilities disclosed in DSA-2026-330.

Affected products

  • Dell PowerStore <UNKNOWN>

Timeline

  • 2026-09-01: disclosed

References

Related threats