Junglewise Threat Intelligence

CVE-2026-79687: Dell PowerStore SDNAS missing authentication in critical function

CVE-2026-79687 · Severity: critical · CVSS 9 · Published 2026-09-01

Vendors: Dell.

Executive brief

Dell PowerStore SDNAS is a storage device used by enterprises to manage and store critical business data. CVE-2026-79687 allows an unauthenticated attacker with remote network access to bypass authentication controls and gain unauthorized access to the filesystem, potentially exposing sensitive data, credentials, and enabling full administrative control of the storage system.

Technical details

This is a missing authentication vulnerability in Dell PowerStore SDNAS that allows unauthenticated attackers to access critical functions. The vulnerability is triggered via a remote network attack with medium complexity (AC:H), allowing an attacker to read and potentially write to the filesystem without providing credentials. Exploitation requires no user interaction and can result in high impact to confidentiality, integrity, and availability across the system scope. Dell has issued security updates in DSA-2026-330; affected systems should be patched immediately.

Affected products

  • Dell PowerStore SDNAS <UNKNOWN>

Timeline

  • 2026-09-01: disclosed

References