Description
Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, versions 9.11.0.0 through 9.13.0.2 contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
Published: 2026-07-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell PowerScale OneFS suffers from an insertion of sensitive information into log files. When a low‑privileged user with local access writes data to the system, the application records that data in logs without sanitization, allowing the attacker to view private information that should not be exposed. The vulnerability is classified as CWE‑532 and can compromise confidentiality by leaking stored credentials, configuration details, or other sensitive data. No elevated privileges or remote access are required for the exploitation; the attacker merely needs local, low‑privilege authentication.

Affected Systems

Systems running Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and 9.11.0.0 through 9.13.0.2 are impacted. These versions include the logging component that directly records sensitive content. All affected installations instantiate log files that may store the disclosed data.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, while the EPSS score of less than 1% suggests a low probability of immediate exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, reinforcing that it is not a known, actively exploited threat yet. However, the attack vector is straightforward—any local user with basic permissions can trigger the log write, rendering the weakness potentially impactful in environments where privileged accounts are abundant or poorly monitored.

Generated by OpenCVE AI on August 1, 2026 at 08:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply 261 security update for PowerScale OneFS, which removes the logging vulnerability for all affected versions.
  • Limit local user privileges so that only necessary functions can execute code paths that generate log entries containing sensitive information.
  • Adjust log configuration to exclude or mask sensitive fields, and audit existing log files for unintended disclosures before the patch is applied.

Generated by OpenCVE AI on August 1, 2026 at 08:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Title Sensitive Information Logged in Dell PowerScale OneFS

Tue, 28 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Sensitive Information Logged in Dell PowerScale OneFS

Wed, 22 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Sensitive Information Disclosure in PowerScale OneFS Log Files

Fri, 17 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Sensitive Information Disclosure in PowerScale OneFS Log Files

Thu, 16 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerscale Onefs
Vendors & Products Dell
Dell powerscale Onefs

Wed, 15 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Description Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, versions 9.11.0.0 through 9.13.0.2 contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Powerscale Onefs
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-07-15T15:11:44.976Z

Reserved: 2026-04-14T16:10:47.674Z

Link: CVE-2026-40633

cve-icon Vulnrichment

Updated: 2026-07-15T13:43:03.835Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T09:00:04Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File