CVE-2026-79686
largePrivilege Escalation in Dell PowerStore Storage Appliances
Dell PowerStore contains a protection mechanism failure (CWE-693) that allows an authenticated user with limited privileges to bypass access restrictions and gain escalated privileges on the appliance. The flaw is triggered over the network by a valid low-privileged account, with low attack complexity and no user interaction required, per the CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N). A successful attacker gains high-impact privileges, with the CVSS vector indicating high confidentiality, integrity, and availability impact on the appliance. Any organization running Dell PowerStore appliances where non-administrator accounts exist and the management interface is network-reachable is potentially affected. As of this analysis there is no known public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS puts 30-day exploitation probability at about 0.3% (21st percentile), indicating no confirmed exploitation in the wild.
What to do: Obtain the affected and fixed firmware ranges from Dell's official security advisory and upgrade PowerStore appliances to the patched release. Until patched, restrict network access to PowerStore management interfaces, audit and minimize low-privileged accounts, and monitor non-admin account activity for signs of privilege misuse.
| Dell PowerStore | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access restrictions and gain escalated privileges.
- Weakness
- CWE-693
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.