CVE-2026-58571
largeAuthenticated OS Command Injection in Dell PowerStore Enables Root Command Execution
Dell PowerStore storage appliances contain an OS command injection flaw (CWE-78) that allows an authenticated user with limited privileges to inject and execute arbitrary operating-system commands. Because the attack vector is local (AV:L) with low privileges required, an attacker must first hold valid low-privileged credentials on the appliance, such as a restricted CLI or management-account user, and then submit crafted input that reaches the underlying OS shell. Successful exploitation yields command execution with root privileges, giving the attacker full control over the storage system with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8). Any organization running Dell PowerStore appliances is potentially affected, with exact affected and fixed release ranges available in Dell's security advisory rather than in the summary data. There is no public proof-of-concept, the flaw is not in CISA KEV, and an EPSS of roughly 0.9% indicates low near-term exploitation probability with no confirmed in-the-wild exploitation.
What to do: Upgrade PowerStore systems to the fixed release identified in Dell's security advisory for CVE-2026-58571 as soon as it is published or, if already published, immediately. Until patched, restrict and audit which low-privileged users hold CLI or management access to PowerStore appliances, since exploitation requires valid limited-privilege credentials. There is no public exploit or KEV listing, so priority should be driven by whether untrusted or non-admin users have accounts on these arrays.
| Dell PowerStore (storage appliances) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges.
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.