CVE-2026-58574
largeUnauthenticated info disclosure in Dell PowerStore management interface
Dell PowerStore contains a missing-authentication flaw (CWE-306) in its restricted management interface that allows an unauthenticated attacker with network access to read internal system information from the appliance filesystem. The flaw is triggered simply by sending network requests to the exposed management interface, with no credentials or user interaction required. Because the readable filesystem data can include sensitive information and credentials, an attacker could escalate to full administrative access to the array. Any organization running Dell PowerStore whose management interface is reachable over the network is affected. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS estimates only a 0.3% chance of exploitation within 30 days.
What to do: Check the Dell security advisory for CVE-2026-58574 to identify affected PowerStore versions and upgrade to the patched release Dell provides. Until patched, restrict access to the management interface with network segmentation or firewall rules so unauthenticated users cannot reach it. Because the flaw can expose administrative credentials, prioritize patching arrays on shared or broadly reachable management networks.
| Dell PowerStore | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell PowerStore contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with network access to the restricted management interface could potentially exploit this vulnerability to read internal system information from the appliance filesystem. This is a Critical vulnerability as it could expose sensitive information and credentials which allow full administrative access to the array.
- Weakness
- CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.