CVE-2026-58567
largeOS Command Injection in Dell PowerStore Enables Root-Level Command Execution
Dell PowerStore storage appliances contain an OS command injection vulnerability (CWE-78) in which insufficiently sanitized input is passed to the underlying operating system. The flaw is triggered by an authenticated user with limited privileges, who submits crafted input through the appliance's management functionality, causing arbitrary OS commands to be executed. Because the injected commands run with root privileges, an attacker gains complete control over the appliance, including the ability to read or modify stored data, alter system configuration, or establish persistence. Any organization running affected Dell PowerStore systems where low-privileged accounts exist (for example, restricted support or monitoring users) is exposed. As of now there is no evidence of exploitation in the wild: no public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.5% chance of exploitation within 30 days.
What to do: Review Dell's security advisory (issued by Dell EMC's PSIRT, CNA [email protected]) for the affected and fixed PowerStore releases and apply the patched operating-system/firmware update as soon as a maintenance window allows. In the interim, restrict or audit low-privileged (non-administrator) CLI and management accounts on PowerStore arrays, since those are the required entry point, and limit management-interface access to trusted administrative networks. Because the vector is local (AV:L) and no public exploit exists, prioritize patching arrays that host sensitive data or expose management access to many users.
| Dell PowerStore | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges.
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.