securityonline.info 11 Sept 2026, 01:57 UTC

Dell Warns of Critical ObjectScale Flaw Enabling Remote Code Execution

Dell Warns of Critical ObjectScale Flaw Enabling Remote Code Execution

DELL has issued a security bulletin addressing multiple vulnerabilities in its ObjectScale storage software. The standout flaw is CVE-2026-70416, an unauthenticated remote code execution issue rated CVSS 10.0. The advisory notes that an unauthenticated attacker with remote access could potentially trigger remote code execution, exposing affected Dell ObjectScale deployments to full control compromises.

The report also references additional CVEs tied to ObjectScale, including CVE-2025-43936, CVE-2026-26947, CVE-2025-36591 and CVE-2026-76104, each linked to improper authentication, privilege elevation, broken cryptography and remote denial of service respectively. Dell describes these as vulnerabilities that could enable remote access, local privilege escalation, information disclosure or service disruption across storage clusters.

Dell specifies that all ObjectScale releases prior to 4.4.0[.]0 are affected, with the issues also impacting Dell Elastic Cloud Storage (ECS) versions 3.x through 3.8.1[.]7. The company recommends upgrading to version 4.4.0[.]0 or later, or alternatively moving to 4.2.0[.]1 on supported release trains. When applying the update, administrators should isolate storage management interfaces behind trusted network firewalls to reduce exposure to remote attacks.

The article notes that there is currently no public in‑the‑wild exploitation or PoC for these vulnerabilities, but given the severity of CVE-2026-70416, immediate patching is advised to protect critical object storage and backups.

View full article

Article by CyberSIXT