Description
Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
Published: 2026-09-16
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

This vulnerability is a Deserialization of Untrusted Data flaw that allows an attacker to supply crafted data that is processed by Dell ObjectScale. A successfully exploited instance can execute arbitrary code on the host and compromise the confidentiality, integrity, and availability of the affected system. The flaw stems from insecure handling of object serialization during remote service calls, resulting in unchecked execution of malicious input.

Affected Systems

Dell ObjectScale systems running versions earlier than 4.4.0.0 are affected. These versions expose a deserialization endpoint that accepts untrusted data from remote clients.

Risk and Exploitability

The CVSS score of 10 denotes the highest severity, indicating that exploitation would lead to full compromise if a flaw is triggered. However, the EPSS score is less than 1 percent, implying that, as of the last assessment, the likelihood of seeing real‑world exploitation is very low. The vulnerability is not listed in CISA's KEV catalog. Attackers may remotely exploit it without authentication, using the exposed service endpoints, and are likely to rely on network connectivity to the ObjectScale instance.

Generated by OpenCVE AI on September 18, 2026 at 01:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Dell ObjectScale security update (version 4.4.0.0 or newer) to address the deserialization flaw.
  • Immediately restrict remote access to ObjectScale services by configuring firewall or network segmentation so that only trusted IP ranges can reach the vulnerable endpoints.
  • Perform a vulnerability scan or pen‑test to confirm that the de‑serialization vulnerability has been eliminated, and enable detailed logging on ObjectScale to detect any suspicious payload attempts.

Generated by OpenCVE AI on September 18, 2026 at 01:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:dell:objectscale:*:*:*:*:*:*:*:*

Fri, 18 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell objectscale
Vendors & Products Dell
Dell objectscale

Fri, 18 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Title Untrusted Data Deserialization in Dell ObjectScale Enables Remote Code Execution

Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Dell Objectscale
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-16T17:38:01.919Z

Reserved: 2026-08-04T11:16:10.499Z

Link: CVE-2026-70416

cve-icon Vulnrichment

Updated: 2026-09-16T17:37:56.220Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T16:17:14.953

Modified: 2026-09-21T17:31:02.290

Link: CVE-2026-70416

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T04:30:03Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data