Description
Dell PowerStore contains a Code Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary code with root privileges.
Published: 2026-09-01
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Dell PowerStore suffers from a code injection vulnerability (CWE-94) that allows an authenticated user with limited privileges to execute arbitrary code. If exploited, the attacker can obtain root privileges, enabling full control over the system and its data.

Affected Systems

The vulnerability affects Dell PowerStore storage systems across a broad range of models including the 1000T, 1200T, 3000T, 3200Q, 3200T, 5000T, 500T, 5200Q, 5200T, 7000T, 9000T, and 9200T series. No specific firmware or software version information is provided in the available data, so all current releases of these models should be considered potentially vulnerable.

Risk and Exploitability

The CVSS score of 8.8 reflects a high severity impact. Although the EPSS score is not available, the lack of a KEV listing does not diminish the risk posed by the vulnerability. The requirement for authentication and limited privileges suggests that the attack vector is likely restricted to users who already have some level of access to management interfaces, but an attacker could still elevate to root if the injection succeeds. Given the potential to gain full control, the threat remains significant until a patch is applied.

Generated by OpenCVE AI on September 1, 2026 at 15:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell PowerStore security update 2026-330 from the Dell support site.
  • If the update cannot be applied immediately, block or limit management interface access to users who do not require it and monitor for signs of unauthorized code execution attempts.
  • Once the update is installed, enable only the necessary services and follow Dell’s guidance for hardening the environment to reduce the attack surface.

Generated by OpenCVE AI on September 1, 2026 at 15:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Dell PowerStore Authenticated Code Injection Leading to Root Privilege Escalation
First Time appeared Dell
Dell powerstore 1000t
Dell powerstore 1200t
Dell powerstore 3000t
Dell powerstore 3200q
Dell powerstore 3200t
Dell powerstore 5000t
Dell powerstore 500t
Dell powerstore 5200q
Dell powerstore 5200t
Dell powerstore 7000t
Dell powerstore 9000t
Dell powerstore 9200t
Vendors & Products Dell
Dell powerstore 1000t
Dell powerstore 1200t
Dell powerstore 3000t
Dell powerstore 3200q
Dell powerstore 3200t
Dell powerstore 5000t
Dell powerstore 500t
Dell powerstore 5200q
Dell powerstore 5200t
Dell powerstore 7000t
Dell powerstore 9000t
Dell powerstore 9200t
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description Dell PowerStore contains a Code Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary code with root privileges.
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Dell Powerstore 1000t Powerstore 1200t Powerstore 3000t Powerstore 3200q Powerstore 3200t Powerstore 5000t Powerstore 500t Powerstore 5200q Powerstore 5200t Powerstore 7000t Powerstore 9000t Powerstore 9200t
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-02T03:55:43.865Z

Reserved: 2026-07-01T11:04:36.019Z

Link: CVE-2026-58572

cve-icon Vulnrichment

Updated: 2026-09-01T15:27:28.033Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-01T14:17:37.470

Modified: 2026-09-02T04:17:59.493

Link: CVE-2026-58572

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T16:00:13Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')