Improper Neutralization of CSV File Elements in Dell ECS and ObjectScale
CVE-2026-35157

5.8MEDIUM

Key Information:

Vendor

Dell

Vendor
CVE Published:
11 May 2026

What is CVE-2026-35157?

The vulnerability in Dell ECS and ObjectScale arises from improper handling of formula elements in CSV files within the user interface. This flaw enables an unauthenticated attacker with remote access to potentially exploit the vulnerability, which could result in unauthorized remote code execution. Affected users should take preventative measures to mitigate the risk associated with this security issue.

Affected Version(s)

ECS 0 < 4.3.0.0 or later

ObjectScale 0 < 4.3.0.0 or later

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.