Description
Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability during OS Repository processing to achieve arbitrary command execution as root, potentially leading to full appliance compromise and lateral movement into managed infrastructure.
Published: 2026-07-10
Score: 9.1 Critical
EPSS: 1.2% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an OS command injection caused by improper neutralization of special elements. An attacker with high privileges and remote access can exploit PowerFlex Manager during OS Repository processing to inject arbitrary commands that execute as root. If successful, this gives the attacker full control over the appliance and enables lateral movement into other managed infrastructure.

Affected Systems

Dell PowerFlex Manager versions prior to 5.1.0.1 are affected; any appliance running an affected version is vulnerable.

Risk and Exploitability

The CVSS score of 9.1 indicates a severe risk, while the EPSS score of 1% suggests a low but non-zero probability of exploitation. The vulnerability is not listed in CISA KEV. The likely attack vector is remote access to the PowerFlex Manager interface, inferred from the description, and requires high‑privileged credentials. Exploitation would lead to arbitrary root command execution, full appliance compromise, and potential lateral movement into connected infrastructure.

Generated by OpenCVE AI on July 29, 2026 at 11:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Review Dell's Knowledge Base article (https://www.dell.com/support/kbdoc/en-us/000477538/dsa-2026-066-security-update-for-powerflex-software-multiple-vulnerabilities) for any security updates that address the OS command injection vulnerability in PowerFlex Manager and apply the relevant update if available.
  • Limit remote access to the PowerFlex Manager by restricting high‑privileged accounts to trusted network segments or requiring VPN/strong authentication, ensuring only authorized personnel can reach it.
  • Implement network segmentation or firewall rules to isolate the PowerFlex Manager appliance from untrusted or external networks, reducing the risk of lateral movement if the appliance were compromised.

Generated by OpenCVE AI on July 29, 2026 at 11:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Root-Privilege OS Command Injection in Dell PowerFlex Manager

Sat, 25 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Root-Privilege OS Command Injection in Dell PowerFlex Manager

Tue, 21 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Dell PowerFlex Manager Allows Root Compromise

Fri, 17 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Dell PowerFlex Manager Allows Root Compromise

Tue, 14 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Improper Neutralization of OS Command Leading to Root Execution in Dell PowerFlex Manager

Mon, 13 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Improper Neutralization of OS Command Leading to Root Execution in Dell PowerFlex Manager

Sun, 12 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Dell PowerFlex Manager Allows Arbitrary Root Execution

Sat, 11 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Dell PowerFlex Manager Allows Arbitrary Root Execution

Fri, 10 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerflex Manager
Vendors & Products Dell
Dell powerflex Manager

Fri, 10 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Description Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability during OS Repository processing to achieve arbitrary command execution as root, potentially leading to full appliance compromise and lateral movement into managed infrastructure.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Dell Powerflex Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-07-10T17:01:12.022Z

Reserved: 2026-06-22T17:04:26.238Z

Link: CVE-2026-56688

cve-icon Vulnrichment

Updated: 2026-07-10T16:49:54.255Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T11:15:04Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')