ZeroHour

CVE-2026-76111

large

Incorrect Authorization in Dell PowerStore Enables Authenticated Privilege Escalation

CVSS 3.1
8.8 high
EPSS
<1%p21
Published
()
Modified
AI analysis

Dell PowerStore contains an incorrect authorization flaw (CWE-863) in which certain administrator-only operations are not properly access-controlled. A network-based attacker who already holds a low-privileged, authenticated account on the appliance can invoke these restricted operations directly, with no user interaction required. Successful exploitation grants the attacker elevated (administrator-level) access to the affected system, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8). All Dell PowerStore deployments are potentially affected, particularly environments where untrusted or minimally privileged users are granted access to the system over the network. As of this writing there is no known public proof-of-concept, no entry in the CISA Known Exploited Vulnerabilities catalog, and a low predicted exploitation probability (EPSS ~0.3% over 30 days).

What to do: Upgrade PowerStore OS to the fixed release identified in Dell's security advisory (version ranges were not included in the source data). Until patched, restrict low-privileged accounts and network access to PowerStore management interfaces to trusted users only, and audit recent administrative operations for signs of unauthorized actions. Check the Dell advisory for the definitive list of affected model/version combinations before planning the upgrade.

Affected
Dell PowerStore
Estimated exposure
largetens of thousands of deployed PowerStore systems worldwide — PowerStore is Dell's flagship midrange enterprise storage array with an installed base plausibly in the tens of thousands of systems based on industry deployment patterns, though only users with low-privileged accounts on the appliance…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell PowerStore contains an Incorrect Authorization vulnerability. An authenticated attacker with low privileges could potentially exploit this vulnerability to invoke administrator-only operations, leading to privilege escalation.

Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.