Executive brief
Dell PowerStore is a network-attached storage appliance used by enterprises to store and manage critical data. A flaw in the system's access control mechanism allows authenticated users with basic access rights to bypass security restrictions and gain administrative-level privileges, potentially leading to unauthorized data access, modification, or system compromise.
Technical details
CVE-2026-79686 is a Protection Mechanism Failure vulnerability in Dell PowerStore that enables privilege escalation. An authenticated attacker with low privileges can exploit insufficient access control enforcement in the protection mechanism to bypass authorization checks and escalate to administrative privileges. The vulnerability requires valid user credentials (PR:L) but can be exploited remotely over the network (AV:N) with no user interaction (UI:N). Successful exploitation grants the attacker full control of the system, including the ability to read, modify, or delete data and reconfigure the appliance. Dell has released security updates to remediate this and related vulnerabilities as part of DSA-2026-330.
Affected products
- Dell PowerStore <UNKNOWN>
Timeline
- 2026-09-01: disclosed