Impact
CVE-2026-76111 describes an Incorrect Authorization flaw in Dell PowerStore. An authenticated user with low privileges can exploit the missing access control to invoke operations that are normally reserved for administrators, thereby achieving privilege escalation. The impact is that the attacker can modify or delete critical data, compromise configuration, or otherwise undermine the integrity and confidentiality of the system. This vulnerability corresponds to CWE‑863, Incorrect Authorization.
Affected Systems
Affected systems include Dell PowerStore storage arrays across the 1000T, 1200T, 3000T, 3200Q, 3200T, 5000T, 500T, 5200Q, 5200T, 7000T, 9000T, and 9200T series. No specific firmware or software version information was provided in the advisory; all models listed are vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting limited public exploitation data. The attack vector requires an authenticated user with low privileges; from that position the attacker can exploit the missing authorization check to call administrative functions. It requires only valid credentials and no additional conditions, making the exploitation path relatively straightforward for a malicious insider or compromised account.
OpenCVE Enrichment