Description
Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
Published: 2026-08-17
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell ObjectScale versions before 4.3.0.1 contain a path traversal flaw that allows a low‑privileged local attacker to read files outside the intended directories, potentially exposing sensitive data such as configuration files or credentials.

Affected Systems

The vulnerability affects Dell ObjectScale deployments running any version prior to 4.3.0.1. Updating to 4.3.0.1 or later removes the flaw.

Risk and Exploitability

The CVSS score of 3.3 reflects a low‑severity risk. Because the vulnerability requires local access at a privilege level below that of a system administrator, it is not exploitable over the network. No EPSS data is available and the issue is not listed in CISA KEV, indicating there are currently no public exploits or widespread active attacks reported.

Generated by OpenCVE AI on August 17, 2026 at 15:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dell ObjectScale to version 4.3.0.1 or later to eliminate the path traversal flaw
  • Restrict local access to the ObjectScale installation to trusted administrators and eliminate unnecessary local privileges
  • Monitor system logs for attempts to read files outside the designated directories and investigate any suspicious activity

Generated by OpenCVE AI on August 17, 2026 at 15:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:dell:objectscale:*:*:*:*:*:*:*:*

Mon, 17 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell objectscale
Vendors & Products Dell
Dell objectscale

Mon, 17 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Title Path Traversal in Dell ObjectScale Leading to Information Disclosure

Mon, 17 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Description Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
Weaknesses CWE-35
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Dell Objectscale
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-17T14:47:37.577Z

Reserved: 2026-06-18T17:04:56.016Z

Link: CVE-2026-56089

cve-icon Vulnrichment

Updated: 2026-08-17T14:47:33.977Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-17T14:20:20.920

Modified: 2026-08-19T01:12:03.567

Link: CVE-2026-56089

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T16:30:06Z

Weaknesses
  • CWE-35

    Path Traversal: '.../...//'