Description
Dell PowerStore contains a Missing Authorization vulnerability. An attacker with access to a mapped host could exploit this vulnerability to read from or write to LUNs that the host is not authorized to access, bypassing per-initiator LUN access controls and leading to protection mechanism bypass.
Published: 2026-08-18
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing‑authorization flaw identified as CWE‑862. It allows an attacker who has access to a mapped host to read from or write to LUNs that the host is not authorized to use, bypassing per‑initiator LUN access controls. This results in unauthorized data exposure, tampering, and potential disruption of services, thereby compromising confidentiality, integrity, and availability.

Affected Systems

The vulnerability affects multiple Dell PowerStore models, including the 1000T, 1200T, 3000T, 3200Q, 3200T, 5000T, 500T, 5200Q, 5200T, 7000T, 9000T and 9200T series. No specific firmware or model version is listed; any system with a mapped host that connects to LUNs is potentially susceptible.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity. EPSS data is unavailable and the exposure is not listed in the CISA KEV catalog. Attacks would likely require the attacker to have network or host access to a mapped host that communicates with the PowerStore array. With such access, the attacker can exploit the missing authorization to bypass LUN permissions and perform unauthorized read/write operations.

Generated by OpenCVE AI on August 18, 2026 at 19:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Dell PowerStore firmware update that addresses the missing‑authorization issue (download from Dell support KB 497829).
  • Configure each host’s initiator ID to enforce per‑initiator LUN access controls, ensuring no wildcard or default initiators are permitted.
  • If a firmware update is delayed, isolate or remove the affected host from the storage pool until the fix is applied.

Generated by OpenCVE AI on August 18, 2026 at 19:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Title Missing Authorization Enables Unauthorized LUN Access in Dell PowerStore

Tue, 18 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerstore 1000t
Dell powerstore 1200t
Dell powerstore 3000t
Dell powerstore 3200q
Dell powerstore 3200t
Dell powerstore 5000t
Dell powerstore 500t
Dell powerstore 5200q
Dell powerstore 5200t
Dell powerstore 7000t
Dell powerstore 9000t
Dell powerstore 9200t
Vendors & Products Dell
Dell powerstore 1000t
Dell powerstore 1200t
Dell powerstore 3000t
Dell powerstore 3200q
Dell powerstore 3200t
Dell powerstore 5000t
Dell powerstore 500t
Dell powerstore 5200q
Dell powerstore 5200t
Dell powerstore 7000t
Dell powerstore 9000t
Dell powerstore 9200t

Tue, 18 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Description Dell PowerStore contains a Missing Authorization vulnerability. An attacker with access to a mapped host could exploit this vulnerability to read from or write to LUNs that the host is not authorized to access, bypassing per-initiator LUN access controls and leading to protection mechanism bypass.
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Powerstore 1000t Powerstore 1200t Powerstore 3000t Powerstore 3200q Powerstore 3200t Powerstore 5000t Powerstore 500t Powerstore 5200q Powerstore 5200t Powerstore 7000t Powerstore 9000t Powerstore 9200t
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-19T03:56:08.836Z

Reserved: 2026-07-29T11:04:32.678Z

Link: CVE-2026-67262

cve-icon Vulnrichment

Updated: 2026-08-18T19:52:25.235Z

cve-icon NVD

Status : Received

Published: 2026-08-18T18:19:24.927

Modified: 2026-08-19T04:17:37.523

Link: CVE-2026-67262

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T19:30:04Z

Weaknesses