Description
Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and versions 9.11.0.0 through 9.13.0.2 contains an Improper Privilege Management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Published: 2026-07-15
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an Improper Privilege Management flaw (CWE‑269) that allows a local attacker who already has administrative privileges in Dell PowerScale OneFS to further increase their own privileges. This escalation could enable the attacker to modify data, services, or configuration settings beyond their original authority, potentially compromising the integrity and availability of the storage appliance.

Affected Systems

Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7 and 9.11.0.0 through 9.13.0.2 are affected. These versions include the identified privilege‑management flaw and are susceptible to local privilege escalation when accessed by a user with high‑privileged credentials.

Risk and Exploitability

The CVSS score of 6.7 indicates moderate severity, while the EPSS score of less than 1 % denotes a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local access by a user who already has high‑privileged rights; no network or remote attack vector is documented. Because elevation of privileges on a storage appliance can have significant operational impact, applying the vendor‑issued firmware update that addresses this flaw is strongly recommended.

Generated by OpenCVE AI on August 1, 2026 at 09:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Dell PowerScale OneFS firmware update that contains the privilege‑management fix without delay.
  • Reduce or disable unused local administrative accounts to minimize attacker footholds.
  • Enforce least privilege by assigning only necessary roles to local users and conducting regular privilege audits.

Generated by OpenCVE AI on August 1, 2026 at 09:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Title Improper Privilege Management Vulnerability Enabling Local Privilege Escalation in Dell PowerScale OneFS

Wed, 29 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Elevation of Privileges in Dell PowerScale OneFS via Improper Privilege Management

Sun, 26 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Elevation of Privileges in Dell PowerScale OneFS via Improper Privilege Management

Wed, 22 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Elevation of Privileges via Improper Privilege Management in Dell PowerScale OneFS

Fri, 17 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Elevation of Privileges via Improper Privilege Management in Dell PowerScale OneFS

Thu, 16 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerscale Onefs
Vendors & Products Dell
Dell powerscale Onefs

Wed, 15 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Description Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and versions 9.11.0.0 through 9.13.0.2 contains an Improper Privilege Management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Powerscale Onefs
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-07-16T03:55:21.048Z

Reserved: 2026-05-31T17:04:24.517Z

Link: CVE-2026-49501

cve-icon Vulnrichment

Updated: 2026-07-15T17:43:57.854Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T09:15:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management