ZeroHour

CVE-2026-79682

large

Authenticated Command Injection (Root Privilege Escalation) in Dell PowerStore

CVSS 3.1
8.8 high
EPSS
<1%p43
Published
()
Modified
AI analysis

CVE-2026-79682 is a command injection flaw (CWE-77) in Dell PowerStore, Dell's enterprise midrange all-flash storage array line. An authenticated user with limited (low) privileges can trigger the flaw, which allows execution of arbitrary operating system commands with root privileges on the appliance. Because the vector is local (CVSS 3.1 AV:L) but scope is changed, a successful attacker gains full control of the affected PowerStore system, including complete confidentiality, integrity and availability impact, effectively a privilege escalation from a restricted account to root. Organizations operating Dell PowerStore arrays — typically enterprise and mid-market data centers — are the affected population, though exploitation requires credentials for a low-privilege account on the appliance. As of now there is no public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS gives it a 0.5% probability of exploitation in the next 30 days, so no active exploitation is known.

What to do: Apply the PowerStore OS update identified in Dell's security advisory for this CVE — check the advisory for your specific model's affected and fixed releases rather than assuming from this data. Until patched, limit and audit accounts holding low-privilege roles on PowerStore management interfaces and review logs for unexpected command execution or administrative activity. No public PoC or in-the-wild exploitation is known, so prioritize patching within normal maintenance windows but verify against Dell's guidance for completeness.

Affected
Dell PowerStore (PowerStore OS appliance software)
Estimated exposure
largetens of thousands of deployed PowerStore arrays worldwide (estimated) — PowerStore, launched in 2020 as Dell's midrange all-flash array family, is estimated to have an enterprise installed base on the order of tens of thousands of systems based on typical enterprise storage shipment patterns; because the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell PowerStore contains a Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges.

Weakness
CWE-77
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.