Description
Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution.
Published: 2026-08-17
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an OS Command Injection flaw (CWE‑78) that allows a low‑privileged attacker with local access to execute arbitrary operating‑system commands. The exploitation would compromise the confidentiality, integrity, and availability of the affected system by enabling unauthorized command execution.

Affected Systems

Dell ObjectScale versions prior to 4.3.0.1 are affected. All releases before the 4.3.0.1 update contain the vulnerability and are therefore vulnerable.

Risk and Exploitability

The CVSS score of 7.3 classifies this flaw as high risk. While EPSS data is not available, the flaw currently is not listed in the CISA KEV catalog. Exploitation requires local access and a low‑privileged account, indicating that the attack surface is restricted to individuals with physical or local network presence on the system.

Generated by OpenCVE AI on August 17, 2026 at 15:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell ObjectScale security update to version 4.3.0.1 or higher
  • Restrict local user privileges to prevent low‑privileged accounts from accessing vulnerable code paths
  • Sanitize all input used in OS command execution and avoid passing unsanitized data to shell commands

Generated by OpenCVE AI on August 17, 2026 at 15:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell objectscale
Vendors & Products Dell
Dell objectscale

Mon, 17 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Objectscale
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-17T13:40:04.595Z

Reserved: 2026-06-22T17:04:26.238Z

Link: CVE-2026-56685

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-17T14:20:21.193

Modified: 2026-08-17T14:20:21.193

Link: CVE-2026-56685

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T15:30:06Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')