Description
Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Published: 2026-08-17
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell ObjectScale versions prior to 4.3.0.1 contain an Uncontrolled Search Path Element vulnerability that allows a local, low‑privileged attacker to modify the search path used by the software. By inserting directory entries that precede trusted locations, an attacker can cause the system to load malicious code or override executables, leading to unauthorized execution of privileged code and a full escalation of privileges.

Affected Systems

Dell ObjectScale; any instance running a release earlier than 4.3.0.1 is susceptible to this vulnerability.

Risk and Exploitability

The vulnerability has a CVSS score of 7.3, indicating a high severity. EPSS information is not available, and the issue has not been listed in CISA’s KEV catalog. The attack requires local access and a low‑privileged user role, so while exploitation is feasible, it depends on an attacker gaining local access to the system. The combination of a high severity score and the local attack vector presents a significant risk to affected deployments.

Generated by OpenCVE AI on August 17, 2026 at 15:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell ObjectScale security update 4.3.0.1 or later to correct the unsafe search path handling
  • Restrict or hard‑code the PATH environment variable used by ObjectScale so that only trusted system directories are in use and prevent user modification
  • Limit local user privileges on ObjectScale servers to reduce the ability of low‑privileged accounts to alter execution paths

Generated by OpenCVE AI on August 17, 2026 at 15:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell objectscale
Vendors & Products Dell
Dell objectscale

Mon, 17 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Weaknesses CWE-427
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Objectscale
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-17T13:44:51.051Z

Reserved: 2026-06-18T17:04:56.016Z

Link: CVE-2026-56090

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-17T14:20:21.077

Modified: 2026-08-17T14:20:21.077

Link: CVE-2026-56090

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T15:30:06Z

Weaknesses
  • CWE-427

    Uncontrolled Search Path Element