Description
Dell PowerScale OneFS, versions 9.5.0.0 through 9.7.1.15, versions 9.8.0.0 through 9.13.1.0, and versions prior to 9.15.0.0, contain an Incorrect Authorization vulnerability. A low privileged adjacent network attacker could potentially exploit this vulnerability, leading to unauthorized modification of system logs.
Published: 2026-09-09
Score: 3.5 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell PowerScale OneFS housing systems can have their system logs wrongly altered by an attacker with low‑privilege access to the adjacent network, due to an Incorrect Authorization flaw. This permits the attacker to modify log entries, which can undermine forensic analysis and conceal malicious activity, compromising data integrity in the logs.

Affected Systems

The flaw affects Dell PowerScale OneFS versions 9.5.0.0 through 9.7.1.15, 9.8.0.0 through 9.13.1.0, and all releases before 9.15.0.0. Systems running any of those firmware builds are vulnerable.

Risk and Exploitability

The CVSS score of 3.5 reflects a low‑severity risk; the EPSS score is not available and the vulnerability is not listed in CISA's KEV catalog, indicating no known widespread exploitation. Based on the description, the attacker must have network access to the OneFS environment and only basic privileges, so the risk is limited to potential log tampering rather than full system compromise. Based on the description, the likely attack vector is an adjacent network connection, implying that exploitation is probable only from that local access.

Generated by OpenCVE AI on September 9, 2026 at 18:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell PowerScale OneFS security update referenced in DSA‑2026‑360.
  • Restrict network connectivity to OneFS management interfaces to trusted hosts only to prevent low‑privilege network attackers.
  • Configure and monitor audit logs for unauthorized modifications to detect and respond to tampering attempts.

Generated by OpenCVE AI on September 9, 2026 at 18:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege Authorization Bypass Allows Log Tampering on Dell PowerScale OneFS

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Dell PowerScale OneFS, versions 9.5.0.0 through 9.7.1.15, versions 9.8.0.0 through 9.13.1.0, and versions prior to 9.15.0.0, contain an Incorrect Authorization vulnerability. A low privileged adjacent network attacker could potentially exploit this vulnerability, leading to unauthorized modification of system logs.
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-09T16:57:06.506Z

Reserved: 2026-05-14T17:05:39.858Z

Link: CVE-2026-46460

cve-icon Vulnrichment

Updated: 2026-09-09T16:56:55.245Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-09T17:17:21.370

Modified: 2026-09-09T20:14:26.883

Link: CVE-2026-46460

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T18:30:13Z

Weaknesses