Improper Authentication in Dell PowerFlex Manager
CVE-2026-49502

7.4HIGH

Key Information:

Vendor

Dell

Status
Vendor
CVE Published:
17 June 2026

What is CVE-2026-49502?

Dell PowerFlex Manager has a vulnerability that allows unauthenticated attackers with adjacent network access to exploit the system. This flaw can lead to significant risks, including potential information disclosure, tampering of data, and unauthorized access to sensitive resources. It is crucial for users to be aware of this vulnerability to implement necessary precautions.

Affected Version(s)

PowerFlex 0 < 5.1.0.1 or later

PowerFlex 0 < 4.5.5.2 or later

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dell would like to thank brocked200 for reporting this issue.
.