CVE-2026-70425

Summary

Dell PowerScale OneFS, Versions 9.5.0.0 through 9.7.1.0, Versions 9.8.0.0 through 9.10.1.0, and Versions 9.11.0.0 through 9.14.0.1, contain a command injection vulnerability. An admin privileged local attacker could potentially exploit this vulnerability, leading to elevation of privileges to root, impacting confidentiality, integrity, and availability.

Affected Software

VendorProductVersion RangeStatus
DellPowerScale OneFS0 < 9.13.1.1 or lateraffected
DellPowerScale OneFS0 < 9.15.0.0 or lateraffected

Weaknesses

  • CWE-78: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

References