Description
Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering.
Published: 2026-08-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell ObjectScale versions prior to 4.3.0.1 contain a path traversal vulnerability (CWE-35). A low‑privileged local attacker could traverse directory boundaries to access or modify files, potentially tampering with sensitive data. The flaw enables modification of configuration or data files, undermining integrity.

Affected Systems

Dell ObjectScale, versions before 4.3.0.1, is affected. No specific CPE listed; the vulnerability affects all installations of that product.

Risk and Exploitability

The CVSS score is 7.1, indicating a high impact. The EPSS score is unknown and the vulnerability is not in CISA KEV. Local access with low privileges is required; the attacker must be able to login locally or have a compromised account. The path traversal can be leveraged to tamper with data, though this requires local privilege.

Generated by OpenCVE AI on August 17, 2026 at 15:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dell ObjectScale to version 4.3.0.1 or later to remove the path traversal flaw.
  • If an upgrade is not possible, apply Dell’s security update for ObjectScale as described in the advisory at https://www.dell.com/support/kbdoc/en-us/000500724/dsa-2026-328-security-update-for-dell-objectscale-multiple-proprietary-code-vulnerabilities.
  • Review and restrict local user privileges; ensure the ObjectScale service runs with the least privilege so that a low‑privileged attacker cannot exploit the path traversal.

Generated by OpenCVE AI on August 17, 2026 at 15:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:dell:objectscale:*:*:*:*:*:*:*:*

Tue, 18 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell objectscale
Vendors & Products Dell
Dell objectscale

Mon, 17 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability in Dell ObjectScale Allowing Local Information Tampering

Mon, 17 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Description Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering.
Weaknesses CWE-35
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

Dell Objectscale
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-18T14:42:25.444Z

Reserved: 2026-07-07T17:04:34.467Z

Link: CVE-2026-59909

cve-icon Vulnrichment

Updated: 2026-08-18T14:42:21.090Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-17T14:20:21.487

Modified: 2026-08-19T01:11:11.413

Link: CVE-2026-59909

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T17:30:18Z

Weaknesses
  • CWE-35

    Path Traversal: '.../...//'