CVE-2026-58569
largeLocal privilege escalation to root in Dell PowerStore (untrusted functionality inclusion)
Dell PowerStore arrays contain a CWE-829 'Inclusion of Functionality from Untrusted Control Sphere' flaw, meaning the appliance loads or incorporates functionality (such as code or libraries) from a source outside its trusted control boundary. An authenticated user with only limited privileges who has local access to the system can trigger the flaw, and no user interaction is required. Successful exploitation lets the attacker execute arbitrary code with root privileges on the array, effectively a full compromise of the appliance (CVSS scope change with high confidentiality, integrity, and availability impact). Any organization running an affected Dell PowerStore system is exposed, particularly where low-privileged users can authenticate to local or management interfaces on the appliance. Exploitation status is quiet so far: no public proof of concept, not listed in CISA's KEV catalog, and EPSS estimates only about a 0.1% probability of exploitation within 30 days.
What to do: Upgrade PowerStore systems to the fixed release identified in Dell's security advisory (the available data does not specify affected or fixed version numbers). Until patched, restrict which accounts can authenticate locally to PowerStore (for example SSH and management interfaces) and remove unnecessary low-privileged access, since exploitation requires an authenticated local session. Check Dell's advisory for exact affected version ranges and schedule the update at the next maintenance window.
| Dell PowerStore | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell PowerStore contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary code with root privileges..
- Weakness
- CWE-829
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.