CVE-2026-79684
largePrivilege Escalation via Access-Restriction Bypass in Dell PowerStore
Dell PowerStore, Dell's midrange all-flash storage appliance line, contains a protection mechanism failure (CWE-693) that allows access restrictions to be bypassed. An attacker who already holds a low-privileged authenticated account on the appliance can trigger the flaw over the network with low complexity and no user interaction (CVSS:3.1/AV:N/AC:L/PR:L/UI:N), most plausibly through the appliance's management interface. Successful exploitation yields escalated privileges with high impact on confidentiality, integrity, and availability, reflected in the 8.8 (High) CVSS 3.1 score. Any organization running an affected PowerStore release is exposed, but Dell has not specified affected version ranges in the available data, so administrators should consult Dell's security advisory for exact scoping. There is no known public proof-of-concept, the flaw is not listed in CISA KEV, and no in-the-wild exploitation is known; EPSS estimates only about a 0.3% probability of exploitation within 30 days.
What to do: Upgrade PowerStore to the fixed release identified in Dell's security advisory for CVE-2026-79684 (specific fixed versions were not included in the data available here). In the interim, audit local and directory-integrated PowerStore accounts for unexpected privilege assignments and restrict management interface access to trusted administrative networks. Since no in-the-wild exploitation is known, patching during normal maintenance windows with monitoring of Dell's advisory for updates is a reasonable posture.
| Dell PowerStore | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access restrictions and gain escalated privileges.
- Weakness
- CWE-693
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.