Description
Dell ObjectScale, versions prior to 4.4.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability in the OS. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.
Published: 2026-09-16
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service due to incorrect permission assignment on critical OS resources
Action: Patch immediately
AI Analysis

Impact

Dell ObjectScale versions prior to 4.4.0.0 contain an incorrect permission assignment on a critical OS resource. A high‑privileged attacker who can reach the system remotely could exploit this misconfiguration, potentially causing a denial of service for legitimate users. The vulnerability does not expose sensitive data and does not allow code execution, but it can disrupt service availability.

Affected Systems

Dell ObjectScale products – all releases before version 4.4.0.0 are affected. The vulnerability applies to the operating system layer of the ObjectScale stack.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity. The EPSS score is under 1%, reflecting a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote access from a high‑privileged attacker, as stated in the description. Successful exploitation would lead to service disruption but does not compromise confidentiality or integrity of data.

Generated by OpenCVE AI on September 18, 2026 at 02:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy the Dell ObjectScale security update dsa-2026-393 to correct the permission assignment on critical OS resources.
  • Reconfigure the OS privilege settings so that only required service accounts have write access to the affected resources, following the default security settings in the patch documentation.
  • Restrict general remote administrative access by enabling multi‑factor authentication and limiting privileged operations to a narrow set of trusted accounts during and after the update.

Generated by OpenCVE AI on September 18, 2026 at 02:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:dell:objectscale:*:*:*:*:*:*:*:*

Fri, 18 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell objectscale
Vendors & Products Dell
Dell objectscale

Fri, 18 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Title Incorrect Permission Assignment in Dell ObjectScale OS Leading to Denial of Service

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Dell ObjectScale, versions prior to 4.4.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability in the OS. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.
Weaknesses CWE-732
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H'}


Subscriptions

Dell Objectscale
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-16T18:35:21.704Z

Reserved: 2026-08-18T23:05:02.337Z

Link: CVE-2026-76104

cve-icon Vulnrichment

Updated: 2026-09-16T18:18:42.750Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T16:17:15.503

Modified: 2026-09-21T17:30:54.300

Link: CVE-2026-76104

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T04:30:03Z

Weaknesses
  • CWE-732

    Incorrect Permission Assignment for Critical Resource