Description
Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
Published: 2026-09-16
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an Improper Authentication flaw in Dell ObjectScale running versions earlier than 4.4.0.0. It permits an unauthenticated attacker with remote access to bypass the system’s authentication controls and gain unauthorized access, potentially exposing data and configuration settings.

Affected Systems

All installations of Dell ObjectScale prior to version 4.4.0.0 are affected. The flaw applies to the overall product as no subcomponent is singled out, so any older release could be vulnerable if exposed to remote exposure.

Risk and Exploitability

The CVSS score of 8.1 classifies the flaw as high severity. The EPSS score of less than 1% indicates a low likelihood of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote and unauthenticated, meaning an attacker could exploit the flaw from outside the network if the system is reachable. Because the impact is high while the exploitation probability is relatively low, the recommended response is to patch promptly while maintaining vigilance for any incidents.

Generated by OpenCVE AI on September 18, 2026 at 00:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Dell ObjectScale 4.4.0.0 or later to apply the official security update that resolves the authentication flaw.
  • If an upgrade cannot be applied immediately, isolate the ObjectScale service behind a firewall, restrict inbound connections to trusted IP addresses, or place it in a separate VLAN to limit exposure to unauthenticated remote attacks.
  • Continuously monitor system logs and authentication events for indications of unauthorized attempts, and configure alerts to notify the security team when suspicious activity is detected.

Generated by OpenCVE AI on September 18, 2026 at 00:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:dell:objectscale:*:*:*:*:*:*:*:*

Fri, 18 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell objectscale
Vendors & Products Dell
Dell objectscale

Fri, 18 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Title Improper Authentication in Dell ObjectScale Enables Remote Unauthorized Access

Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Objectscale
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-17T03:57:05.705Z

Reserved: 2025-04-20T05:04:01.414Z

Link: CVE-2025-43936

cve-icon Vulnrichment

Updated: 2026-09-16T17:25:21.884Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T16:17:02.877

Modified: 2026-09-21T17:31:09.390

Link: CVE-2025-43936

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:15:06Z

Weaknesses