Description
Dell PowerStore contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary code with root privileges..
Published: 2026-09-01
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Dell PowerStore contains an inclusion of functionality from an untrusted control sphere. An authenticated user with limited privileges could potentially exploit this flaw to run arbitrary code with root privileges, thereby compromising confidentiality, integrity, and availability. The weakness is classified as CWE‑829, indicating that the software incorrectly incorporates or processes functionality supplied by an untrusted source.

Affected Systems

Dell PowerStore storage arrays, including models 1000T, 1200T, 3000T, 3200Q, 3200T, 5000T, 500T, 5200Q, 5200T, 7000T, 9000T, and 9200T. No version information is provided in the data, so all releases of these models are potentially affected.

Risk and Exploitability

The CVSS score is 8.8, indicating high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires an authenticated user with limited privileges, implying that the threat actor must first gain legitimate or compromised credentials and access the management interface or internal network. Once the vulnerable functionality is invoked, the attacker can execute code with root privileges, making exploitation highly destructive.

Generated by OpenCVE AI on September 1, 2026 at 16:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell security update described in the Dell Knowledge Base article linked in the advisory.
  • If the update cannot be applied immediately, block or disable the vulnerable functionality and enforce strict role‑based access controls on the PowerStore management interface.
  • Isolate affected PowerStore arrays between the administrative network and other services, and implement logging and monitoring for unusual root‑level actions.

Generated by OpenCVE AI on September 1, 2026 at 16:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 05 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Inclusion of Untrusted Functionality Allows Root Privilege Escalation on Dell PowerStore

Tue, 01 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerstore 1000t
Dell powerstore 1200t
Dell powerstore 3000t
Dell powerstore 3200q
Dell powerstore 3200t
Dell powerstore 5000t
Dell powerstore 500t
Dell powerstore 5200q
Dell powerstore 5200t
Dell powerstore 7000t
Dell powerstore 9000t
Dell powerstore 9200t
Vendors & Products Dell
Dell powerstore 1000t
Dell powerstore 1200t
Dell powerstore 3000t
Dell powerstore 3200q
Dell powerstore 3200t
Dell powerstore 5000t
Dell powerstore 500t
Dell powerstore 5200q
Dell powerstore 5200t
Dell powerstore 7000t
Dell powerstore 9000t
Dell powerstore 9200t

Tue, 01 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Dell PowerStore contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary code with root privileges..
Weaknesses CWE-829
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Dell Powerstore 1000t Powerstore 1200t Powerstore 3000t Powerstore 3200q Powerstore 3200t Powerstore 5000t Powerstore 500t Powerstore 5200q Powerstore 5200t Powerstore 7000t Powerstore 9000t Powerstore 9200t
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-04T19:55:56.393Z

Reserved: 2026-07-01T11:04:36.019Z

Link: CVE-2026-58569

cve-icon Vulnrichment

Updated: 2026-09-04T19:55:53.412Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-09-01T15:17:21.187

Modified: 2026-09-04T20:17:24.137

Link: CVE-2026-58569

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T16:30:17Z

Weaknesses
  • CWE-829

    Inclusion of Functionality from Untrusted Control Sphere