ZeroHour

CVE-2026-79684

large

Privilege Escalation via Access-Restriction Bypass in Dell PowerStore

CVSS 3.1
8.8 high
EPSS
<1%p28
Published
()
Modified
AI analysis

Dell PowerStore, Dell's midrange all-flash storage appliance line, contains a protection mechanism failure (CWE-693) that allows access restrictions to be bypassed. An attacker who already holds a low-privileged authenticated account on the appliance can trigger the flaw over the network with low complexity and no user interaction (CVSS:3.1/AV:N/AC:L/PR:L/UI:N), most plausibly through the appliance's management interface. Successful exploitation yields escalated privileges with high impact on confidentiality, integrity, and availability, reflected in the 8.8 (High) CVSS 3.1 score. Any organization running an affected PowerStore release is exposed, but Dell has not specified affected version ranges in the available data, so administrators should consult Dell's security advisory for exact scoping. There is no known public proof-of-concept, the flaw is not listed in CISA KEV, and no in-the-wild exploitation is known; EPSS estimates only about a 0.3% probability of exploitation within 30 days.

What to do: Upgrade PowerStore to the fixed release identified in Dell's security advisory for CVE-2026-79684 (specific fixed versions were not included in the data available here). In the interim, audit local and directory-integrated PowerStore accounts for unexpected privilege assignments and restrict management interface access to trusted administrative networks. Since no in-the-wild exploitation is known, patching during normal maintenance windows with monitoring of Dell's advisory for updates is a reasonable posture.

Affected
Dell PowerStore
Estimated exposure
largeTens of thousands of deployed PowerStore systems worldwide (order-of-magnitude install-base estimate, not a public-scan figure) — PowerStore is Dell's flagship midrange array line launched in 2020 with a substantial enterprise install base, but no published install counts or internet-exposure scan data were available, and exploitation additionally requires an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access restrictions and gain escalated privileges.

Weakness
CWE-693
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.