Description
Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Improper Privilege Management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Published: 2026-09-16
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

Dell ECS and ObjectScale expose an improper privilege management flaw. A local attacker who already possesses high‑privileged access can exploit this weakness to elevate their privileges further, potentially gaining administrative control over the system. The vulnerability is a classic example of CWE‑269, where insufficient checks on permissions allow privilege escalation.

Affected Systems

Affected versions are Dell ECS releases 3.8.1.0 through 3.8.1.7 and Dell ObjectScale releases earlier than 4.4.0.0. These are identified by Dell under their ECS product line, which is used for object storage and data protection.

Risk and Exploitability

The CVSS base score of 6.7 reflects a moderate severity, and the EPSS score of less than 1 % indicates a low probability of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog, meaning no known large‑scale attacks have been documented. Exploitation requires local, high‑privileged access, so the attack vector is local. Because the required access is already privileged, the risk lies in an attacker extending that control to obtain full system authority.

Generated by OpenCVE AI on September 18, 2026 at 01:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Dell security update that patches ECS to version 3.8.1.8 or later, or upgrade to ObjectScale 4.4.0.0 or later.
  • Restrict local administrative access by enforcing least‑privilege principles and disabling unused local accounts.
  • Review and harden local account permissions to ensure that privilege escalation cannot occur from existing high‑privileged users.
  • Continuously monitor system logs for unauthorized privilege escalation attempts and respond promptly.

Generated by OpenCVE AI on September 18, 2026 at 01:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell ecs
Vendors & Products Dell
Dell ecs

Fri, 18 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Title Improper Privilege Management in Dell ECS and ObjectScale Leading to Privilege Escalation

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Improper Privilege Management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-18T18:04:54.559Z

Reserved: 2026-02-16T18:04:20.508Z

Link: CVE-2026-26947

cve-icon Vulnrichment

Updated: 2026-09-18T18:04:49.146Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T16:17:07.307

Modified: 2026-09-18T18:17:05.770

Link: CVE-2026-26947

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T04:30:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management