ZeroHour

CVE-2026-58571

large

Authenticated OS Command Injection in Dell PowerStore Enables Root Command Execution

CVSS 3.1
8.8 high
EPSS
<1%p59
Published
()
Modified
AI analysis

Dell PowerStore storage appliances contain an OS command injection flaw (CWE-78) that allows an authenticated user with limited privileges to inject and execute arbitrary operating-system commands. Because the attack vector is local (AV:L) with low privileges required, an attacker must first hold valid low-privileged credentials on the appliance, such as a restricted CLI or management-account user, and then submit crafted input that reaches the underlying OS shell. Successful exploitation yields command execution with root privileges, giving the attacker full control over the storage system with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8). Any organization running Dell PowerStore appliances is potentially affected, with exact affected and fixed release ranges available in Dell's security advisory rather than in the summary data. There is no public proof-of-concept, the flaw is not in CISA KEV, and an EPSS of roughly 0.9% indicates low near-term exploitation probability with no confirmed in-the-wild exploitation.

What to do: Upgrade PowerStore systems to the fixed release identified in Dell's security advisory for CVE-2026-58571 as soon as it is published or, if already published, immediately. Until patched, restrict and audit which low-privileged users hold CLI or management access to PowerStore appliances, since exploitation requires valid limited-privilege credentials. There is no public exploit or KEV listing, so priority should be driven by whether untrusted or non-admin users have accounts on these arrays.

Affected
Dell PowerStore (storage appliances)
Estimated exposure
largetens of thousands of deployed PowerStore systems (estimated; no exact install counts in the provided data) — PowerStore is Dell's mainstream midrange all-flash storage platform sold broadly into enterprise data centers since 2020, making a five-figure installed base plausible, though the local, authenticated attack vector means only environments…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges.

Weakness
CWE-78
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.