Command Injection Vulnerability in Dell PowerScale OneFS
CVE-2026-70425

6.7MEDIUM

Key Information:

Vendor

Dell

Vendor
CVE Published:
9 September 2026

What is CVE-2026-70425?

The command injection vulnerability in Dell PowerScale OneFS allows an administrative-level local adversary to execute arbitrary commands on the system. This can lead to unauthorized elevation of privileges, compromising the security, confidentiality, and availability of the impacted environment. Affected versions include ranges from 9.5.0.0 to 9.14.0.1, emphasizing the need for immediate awareness and action to secure vulnerable systems.

Affected Version(s)

PowerScale OneFS 0 < 9.13.1.1 or later

PowerScale OneFS 0 < 9.15.0.0 or later

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dell would like to thank WinD39 - Huynh Dinh Vu for reporting this issue.
.