Log File Information Disclosure in Dell Elastic Cloud Storage and ObjectScale
CVE-2026-28261

7.8HIGH

Key Information:

Vendor

Dell

Vendor
CVE Published:
8 April 2026

What is CVE-2026-28261?

Dell Elastic Cloud Storage (version 3.8.1.7 and earlier) and Dell ObjectScale (versions prior to 4.1.0.3 and 4.2.0.0) are vulnerable to a log file information disclosure issue. This vulnerability allows a low privileged attacker with local access to potentially exploit the system, leading to exposure of sensitive information stored in log files. The exposed secrets may enable the attacker to gain unauthorized access to the system with the privileges of the compromised account, harming data integrity and confidentiality.

Affected Version(s)

Elastic Cloud Storage 0 < 4.2.0.1 or later

ObjectScale 0 < 4.1.0.3

ObjectScale 0 < 4.2.0.1 or later

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.