Impact
CVE-2026-70425 describes a command injection vulnerability in Dell PowerScale OneFS that can be exploited by an attacker with administrative local privileges. The vulnerability allows execution of arbitrary system commands, leading to elevation of privileges to root. This can compromise confidentiality, integrity, and availability of the entire storage system.
Affected Systems
Affected are Dell PowerScale OneFS releases 9.5.0.0 through 9.7.1.0, 9.8.0.0 through 9.10.1.0, and 9.11.0.0 through 9.14.0.1. Any instance running one of these versions and lacking the published security update is vulnerable.
Risk and Exploitability
The CVSS score of 6.7 indicates a moderate severity. EPSS data is not available and the issue is not listed in CISA's KEV catalog, suggesting limited public exploitation. The attack requires local administrative access; typical vector is via services or interfaces that accept commands. Because the vulnerability results in root privileges, it poses a high impact if an attacker gains the necessary local access.
OpenCVE Enrichment