Impact
Dell PowerStore arrays are affected by an authentication bypass that allows a user already logged in with lower privileges to spoof credentials or sessions and gain Administrator rights. This privilege escalation lets an attacker modify configuration, retrieve sensitive data, and potentially use the system to launch further attacks. The weakness is classified as CWE‑290, improper authentication checks.
Affected Systems
Open Dell PowerStore arrays of the 1000T, 1200T, 3000T, 3200Q, 3200T, 5000T, 500T, 5200Q, 5200T, 7000T, 9000T, and 9200T product lines are impacted. Vendor documentation does not list a specific firmware or software version, so all current deployments without the Dell DSA‑2026‑330 security update are vulnerable.
Risk and Exploitability
The CVSS base score of 8.8 indicates high severity. The EPSS score is not available, so current exploitation probability is unclear, but the risk remains high because the vulnerability requires only an existing authenticated session to be abused. It is not part of the CISA KEV catalog. Attackers with compromised or guessable credentials could exploit this flaw internally to elevate to administrator privilege, helping them pivot into other systems or cause significant damage.
OpenCVE Enrichment