SQL Injection Vulnerability in Dell PowerFlex Manager
CVE-2026-35068

3.5LOW

Key Information:

Vendor

Dell

Status
Vendor
CVE Published:
17 June 2026

What is CVE-2026-35068?

Dell PowerFlex Manager is susceptible to an SQL Injection vulnerability that arises from improper neutralization of special elements used in SQL commands. This flaw allows a low-privileged attacker who has adjacent network access to exploit the vulnerability, potentially leading to unauthorized information disclosure. It is critical for organizations using this software to implement security measures and updates from Dell to safeguard their systems.

Affected Version(s)

PowerFlex 0 < 5.1.0.1 or later

PowerFlex 0 < 4.5.5.2 or later

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.