Description
Dell PowerStore contains an Authentication Bypass by Spoofing vulnerability. An authenticated attacker could potentially exploit this vulnerability to escalate privileges to Administrator.
Published: 2026-09-01
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

Dell PowerStore arrays are affected by an authentication bypass that allows a user already logged in with lower privileges to spoof credentials or sessions and gain Administrator rights. This privilege escalation lets an attacker modify configuration, retrieve sensitive data, and potentially use the system to launch further attacks. The weakness is classified as CWE‑290, improper authentication checks.

Affected Systems

Open Dell PowerStore arrays of the 1000T, 1200T, 3000T, 3200Q, 3200T, 5000T, 500T, 5200Q, 5200T, 7000T, 9000T, and 9200T product lines are impacted. Vendor documentation does not list a specific firmware or software version, so all current deployments without the Dell DSA‑2026‑330 security update are vulnerable.

Risk and Exploitability

The CVSS base score of 8.8 indicates high severity. The EPSS score is not available, so current exploitation probability is unclear, but the risk remains high because the vulnerability requires only an existing authenticated session to be abused. It is not part of the CISA KEV catalog. Attackers with compromised or guessable credentials could exploit this flaw internally to elevate to administrator privilege, helping them pivot into other systems or cause significant damage.

Generated by OpenCVE AI on September 1, 2026 at 15:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the Dell PowerStore security update DSA‑2026‑330 from the Dell support site.
  • Reboot the PowerStore array to apply the firmware changes and ensure updated authentication mechanisms are active.
  • Enforce multi‑factor authentication for all accounts that can access the array and restrict Administrator account usage to essential personnel only.

Generated by OpenCVE AI on September 1, 2026 at 15:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerstore 1000t
Dell powerstore 1200t
Dell powerstore 3000t
Dell powerstore 3200q
Dell powerstore 3200t
Dell powerstore 5000t
Dell powerstore 500t
Dell powerstore 5200q
Dell powerstore 5200t
Dell powerstore 7000t
Dell powerstore 9000t
Dell powerstore 9200t
Vendors & Products Dell
Dell powerstore 1000t
Dell powerstore 1200t
Dell powerstore 3000t
Dell powerstore 3200q
Dell powerstore 3200t
Dell powerstore 5000t
Dell powerstore 500t
Dell powerstore 5200q
Dell powerstore 5200t
Dell powerstore 7000t
Dell powerstore 9000t
Dell powerstore 9200t
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Dell PowerStore contains an Authentication Bypass by Spoofing vulnerability. An authenticated attacker could potentially exploit this vulnerability to escalate privileges to Administrator.
Weaknesses CWE-290
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Powerstore 1000t Powerstore 1200t Powerstore 3000t Powerstore 3200q Powerstore 3200t Powerstore 5000t Powerstore 500t Powerstore 5200q Powerstore 5200t Powerstore 7000t Powerstore 9000t Powerstore 9200t
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-02T03:55:34.943Z

Reserved: 2026-07-01T11:04:36.019Z

Link: CVE-2026-58575

cve-icon Vulnrichment

Updated: 2026-09-01T14:33:28.882Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-01T13:19:52.303

Modified: 2026-09-02T04:17:59.760

Link: CVE-2026-58575

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T16:30:17Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing