CVE-2026-58566
largePrivilege Elevation via Incorrect Authorization in Dell PowerStore
CVE-2026-58566 is an incorrect authorization flaw (CWE-863) in Dell PowerStore storage arrays in which requests from low-privileged users are not properly authorization-checked. A remote attacker who already holds a low-privileged account or role can send a crafted request to the array and, because the check fails, gain elevated privileges on the system. Successful exploitation carries high impact across confidentiality, integrity, and availability (CVSS 3.1 score 8.8), effectively granting attacker administrative-level control over the storage system and its data services. Any organization running Dell PowerStore where low-privileged users or service accounts can reach the array remotely is potentially affected; the affected version ranges are not specified in the available data and should be confirmed via Dell's security advisory. There is currently no known exploitation, no public proof-of-concept, the issue is not in CISA KEV, and EPSS estimates about a 0.2% probability of exploitation within 30 days.
What to do: Consult Dell's security advisory for the affected PowerStore OS versions and apply the patched release Dell provides, since the available data does not specify version ranges. Until patched, restrict access to PowerStore management interfaces to trusted management networks and audit which low-privileged local or directory accounts can reach them. Given the absence of public PoCs and low EPSS, prioritize patching by how exposed and how accessible the array's management plane is.
| Dell PowerStore | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.