Description
Dell PowerStore contains a Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges.
Published: 2026-09-01
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Dell PowerStore suffers from a command injection flaw that permits an authenticated user with limited privileges to inject and run arbitrary commands. The flaw can raise the privileges of the injected command to root, enabling the attacker to modify or delete data, disrupt services, and compromise the entire system’s integrity.

Affected Systems

The vulnerability affects multiple Dell PowerStore models, including 1000T, 1200T, 3000T, 3200Q, 3200T, 5000T, 500T, 5200Q, 5200T, 7000T, 9000T, and 9200T. All devices operating versions listed in the Dell support KB reference are potentially impacted.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity RCE risk. While the EPSS score is not available, the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker must first be authenticated and have limited user rights; from that position, they can trigger the injection, execute arbitrary code, and obtain root-level control. The absence of publicly documented exploit code does not diminish the theoretical exploitability, especially in environments with permissive local access.

Generated by OpenCVE AI on September 2, 2026 at 02:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell PowerStore security update released in the Dell support KB document (https://www.dell.com/support/kbdoc/en-us/000497829/dsa-2026-330-dell-powerstore-t-security-update-for-multiple-vulnerabilities).
  • Restrict authenticated limited‑privilege users from accessing or executing commands that interact with the affected component, applying least‑privilege principles on the device.
  • Isolate affected PowerStore units from external network access until the patch has been applied, effectively reducing the attack surface.

Generated by OpenCVE AI on September 2, 2026 at 02:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerstore 1000t
Dell powerstore 1200t
Dell powerstore 3000t
Dell powerstore 3200q
Dell powerstore 3200t
Dell powerstore 5000t
Dell powerstore 500t
Dell powerstore 5200q
Dell powerstore 5200t
Dell powerstore 7000t
Dell powerstore 9000t
Dell powerstore 9200t
Vendors & Products Dell
Dell powerstore 1000t
Dell powerstore 1200t
Dell powerstore 3000t
Dell powerstore 3200q
Dell powerstore 3200t
Dell powerstore 5000t
Dell powerstore 500t
Dell powerstore 5200q
Dell powerstore 5200t
Dell powerstore 7000t
Dell powerstore 9000t
Dell powerstore 9200t

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Dell PowerStore contains a Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges.
Weaknesses CWE-77
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Dell Powerstore 1000t Powerstore 1200t Powerstore 3000t Powerstore 3200q Powerstore 3200t Powerstore 5000t Powerstore 500t Powerstore 5200q Powerstore 5200t Powerstore 7000t Powerstore 9000t Powerstore 9200t
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-02T03:55:50.213Z

Reserved: 2026-08-25T12:04:33.629Z

Link: CVE-2026-79682

cve-icon Vulnrichment

Updated: 2026-09-01T18:03:57.935Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-01T16:17:19.557

Modified: 2026-09-02T04:18:01.920

Link: CVE-2026-79682

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T03:15:03Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')