Description
Dell PowerStore contains an Incorrect Authorization vulnerability. An authenticated attacker with low privileges could potentially exploit this vulnerability to invoke administrator-only operations, leading to privilege escalation.
Published: 2026-09-01
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

CVE-2026-76111 describes an Incorrect Authorization flaw in Dell PowerStore. An authenticated user with low privileges can exploit the missing access control to invoke operations that are normally reserved for administrators, thereby achieving privilege escalation. The impact is that the attacker can modify or delete critical data, compromise configuration, or otherwise undermine the integrity and confidentiality of the system. This vulnerability corresponds to CWE‑863, Incorrect Authorization.

Affected Systems

Affected systems include Dell PowerStore storage arrays across the 1000T, 1200T, 3000T, 3200Q, 3200T, 5000T, 500T, 5200Q, 5200T, 7000T, 9000T, and 9200T series. No specific firmware or software version information was provided in the advisory; all models listed are vulnerable.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting limited public exploitation data. The attack vector requires an authenticated user with low privileges; from that position the attacker can exploit the missing authorization check to call administrative functions. It requires only valid credentials and no additional conditions, making the exploitation path relatively straightforward for a malicious insider or compromised account.

Generated by OpenCVE AI on September 1, 2026 at 12:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell Security Update DSA‑2026‑330 to all affected PowerStore arrays.
  • Review and enforce role‑based access control, ensuring that only users with proper administrative privileges can execute administrative operations.
  • Continuously monitor PowerStore logs for unexpected administrative commands or signs of privilege escalation.

Generated by OpenCVE AI on September 1, 2026 at 12:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege Escalation via Incorrect Authorization in Dell PowerStore

Tue, 01 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerstore 1000t
Dell powerstore 1200t
Dell powerstore 3000t
Dell powerstore 3200q
Dell powerstore 3200t
Dell powerstore 5000t
Dell powerstore 500t
Dell powerstore 5200q
Dell powerstore 5200t
Dell powerstore 7000t
Dell powerstore 9000t
Dell powerstore 9200t
Vendors & Products Dell
Dell powerstore 1000t
Dell powerstore 1200t
Dell powerstore 3000t
Dell powerstore 3200q
Dell powerstore 3200t
Dell powerstore 5000t
Dell powerstore 500t
Dell powerstore 5200q
Dell powerstore 5200t
Dell powerstore 7000t
Dell powerstore 9000t
Dell powerstore 9200t

Tue, 01 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description Dell PowerStore contains an Incorrect Authorization vulnerability. An authenticated attacker with low privileges could potentially exploit this vulnerability to invoke administrator-only operations, leading to privilege escalation.
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Powerstore 1000t Powerstore 1200t Powerstore 3000t Powerstore 3200q Powerstore 3200t Powerstore 5000t Powerstore 500t Powerstore 5200q Powerstore 5200t Powerstore 7000t Powerstore 9000t Powerstore 9200t
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-01T11:37:36.959Z

Reserved: 2026-08-18T23:05:02.338Z

Link: CVE-2026-76111

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-01T12:17:47.113

Modified: 2026-09-01T12:17:47.113

Link: CVE-2026-76111

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T13:00:16Z

Weaknesses