ZeroHour

CVE-2026-79686

large

Privilege Escalation in Dell PowerStore Storage Appliances

CVSS 3.1
8.8 high
EPSS
<1%p21
Published
()
Modified
AI analysis

Dell PowerStore contains a protection mechanism failure (CWE-693) that allows an authenticated user with limited privileges to bypass access restrictions and gain escalated privileges on the appliance. The flaw is triggered over the network by a valid low-privileged account, with low attack complexity and no user interaction required, per the CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N). A successful attacker gains high-impact privileges, with the CVSS vector indicating high confidentiality, integrity, and availability impact on the appliance. Any organization running Dell PowerStore appliances where non-administrator accounts exist and the management interface is network-reachable is potentially affected. As of this analysis there is no known public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS puts 30-day exploitation probability at about 0.3% (21st percentile), indicating no confirmed exploitation in the wild.

What to do: Obtain the affected and fixed firmware ranges from Dell's official security advisory and upgrade PowerStore appliances to the patched release. Until patched, restrict network access to PowerStore management interfaces, audit and minimize low-privileged accounts, and monitor non-admin account activity for signs of privilege misuse.

Affected
Dell PowerStore
Estimated exposure
large≈10,000–100,000 deployed appliances (Dell's flagship midrange enterprise storage platform) — Dell PowerStore is Dell's mainstream midrange all-flash storage platform deployed across tens of thousands of enterprise sites since its 2020 launch, and exploitability requires only a valid low-privileged account and network access to the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access restrictions and gain escalated privileges.

Weakness
CWE-693
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.