SQL Injection Vulnerability in Dell PowerFlex Manager
CVE-2026-35068
3.5LOW
What is CVE-2026-35068?
Dell PowerFlex Manager is susceptible to an SQL Injection vulnerability that arises from improper neutralization of special elements used in SQL commands. This flaw allows a low-privileged attacker who has adjacent network access to exploit the vulnerability, potentially leading to unauthorized information disclosure. It is critical for organizations using this software to implement security measures and updates from Dell to safeguard their systems.
Affected Version(s)
PowerFlex 0 < 5.1.0.1 or later
PowerFlex 0 < 4.5.5.2 or later