ZeroHour

CVE-2026-58575

large

Authentication bypass (spoofing) in Dell PowerStore allows admin privilege escalation

CVSS 3.1
8.8 high
EPSS
<1%p22
Published
()
Modified
AI analysis

Dell PowerStore contains an authentication bypass by spoofing vulnerability (CWE-290) in which an attacker who already holds a low-privileged authenticated session can spoof an identity or token to bypass authentication checks and escalate to Administrator. The attack is network-based (AV:N), of low complexity, and requires no user interaction, so any account with low-privilege access to the affected PowerStore interfaces is a viable starting point. Successful exploitation yields full Administrator control of the storage appliance, including its configuration and the data it serves. Organizations running affected Dell PowerStore systems are exposed; the advisory data available here does not specify which PowerStore version ranges are affected. No exploitation has been reported: the flaw is not in CISA KEV, there is no known public proof-of-concept, and EPSS estimates only about a 0.3% probability of exploitation within 30 days.

What to do: Check your current PowerStore Operating System version against Dell's security advisory for CVE-2026-58575 and upgrade to the fixed release Dell specifies. Until patching, restrict PowerStore management access to trusted administrative networks, minimize and tightly control low-privileged accounts, and review recent administrative activity for signs of unauthorized elevation.

Affected
Dell PowerStore
Estimated exposure
largetens of thousands of deployed PowerStore systems worldwide (enterprise install base; most reachable only on internal management networks) — Dell has publicly described PowerStore as its fastest-growing midrange storage platform with adoption in over ten thousand customer environments within its first years, implying a deployed-system population in the tens of thousands, though…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell PowerStore contains an Authentication Bypass by Spoofing vulnerability. An authenticated attacker could potentially exploit this vulnerability to escalate privileges to Administrator.

Weakness
CWE-290
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.