Description
Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges.
Published: 2026-09-01
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Root Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

Dell PowerStore suffers an OS Command Injection flaw that permits an authenticated user with limited privileges to execute arbitrary commands as root. The vulnerability is a classic input validation failure (CWE-78) that enables complete control over the underlying host when an attacker gains authenticated access. An attacker can compromise confidentiality, integrity, and availability of the entire storage infrastructure.

Affected Systems

The flaw impacts a broad range of Dell PowerStore models, including the 1000T, 1200T, 3000T, 3200Q, 3200T, 5000T, 500T, 5200Q, 5200T, 7000T, 9000T, and 9200T. No specific firmware or software version identifiers are provided in the public data, so all currently deployed instances should be considered at risk until a patch is applied.

Risk and Exploitability

With a CVSS score of 8.8 the vulnerability is classified as high severity. The EPSS score is unavailable and the weakness is not listed in the CISA KEV catalog, but the exploit requires only legitimate credentials with limited privileges, which may be obtained through phishing or other credential compromise techniques. Once exploited, the attacker achieves root-level execution on the host operating system. The likely attack vector is through authenticated API or web interface usage in a network‑connected environment, implying that remote or local adversaries with valid credentials can trigger the flaw.

Generated by OpenCVE AI on September 1, 2026 at 16:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell PowerStore security update that addresses this command injection flaw; all affected models are covered by the update.
  • Limit or disable low‑privilege accounts that have API or web interface access to the PowerStore system to reduce the attack surface.
  • Enable monitoring of system command execution logs and consider implementing command whitelisting or OS hardening to detect and prevent unauthorized root‑level activity.

Generated by OpenCVE AI on September 1, 2026 at 16:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title OS Command Injection Enables Root Privilege Escalation in Dell PowerStore
First Time appeared Dell
Dell powerstore 1000t
Dell powerstore 1200t
Dell powerstore 3000t
Dell powerstore 3200q
Dell powerstore 3200t
Dell powerstore 5000t
Dell powerstore 500t
Dell powerstore 5200q
Dell powerstore 5200t
Dell powerstore 7000t
Dell powerstore 9000t
Dell powerstore 9200t
Vendors & Products Dell
Dell powerstore 1000t
Dell powerstore 1200t
Dell powerstore 3000t
Dell powerstore 3200q
Dell powerstore 3200t
Dell powerstore 5000t
Dell powerstore 500t
Dell powerstore 5200q
Dell powerstore 5200t
Dell powerstore 7000t
Dell powerstore 9000t
Dell powerstore 9200t
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Dell Powerstore 1000t Powerstore 1200t Powerstore 3000t Powerstore 3200q Powerstore 3200t Powerstore 5000t Powerstore 500t Powerstore 5200q Powerstore 5200t Powerstore 7000t Powerstore 9000t Powerstore 9200t
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-02T03:55:46.014Z

Reserved: 2026-07-01T11:04:36.019Z

Link: CVE-2026-58571

cve-icon Vulnrichment

Updated: 2026-09-01T14:33:34.435Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-01T14:17:37.297

Modified: 2026-09-02T04:17:58.970

Link: CVE-2026-58571

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T17:00:17Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')