Junglewise Threat Intelligence

CVE-2026-79685: Dell PowerStore argument injection in management interface

CVE-2026-79685 · Severity: medium · CVSS 6.5 · Published 2026-09-01

Executive brief

Dell PowerStore is a enterprise storage array used to manage and protect critical business data. The argument injection vulnerability allows authenticated users with limited administrative privileges to exploit the management interface to access sensitive system information they should not have permission to view, potentially exposing credentials and system configuration details.

Technical details

This is an argument injection vulnerability in Dell PowerStore that affects the management interface. An authenticated user with limited privileges can craft malicious argument strings to bypass input validation and execute unauthorized operations. The vulnerability is accessible over the network and requires valid authentication credentials but no elevated privileges to exploit. Successful exploitation allows attackers to read sensitive system information, credentials, and potentially escalate their access level. Patches are available through Dell's security advisory DSA-2026-330.

Affected products

  • Dell PowerStore

Timeline

  • 2026-09-01: disclosed

References

Related threats