CVE-2025-26330: High severity Dell PowerScale OneFS vulnerability
Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an incorrect authorization vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability to access the cluster with previous privileges of a disabled user account.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26330?
CVE-2025-26330 is classified as a medium severity vulnerability due to its potential for unauthorized access by an unauthenticated attacker.
How do I fix CVE-2025-26330?
To fix CVE-2025-26330, update your Dell PowerScale OneFS software to a version higher than 9.10.0.1.
Who is affected by CVE-2025-26330?
Users of Dell PowerScale OneFS versions 9.4.0.0 through 9.10.0.1 are affected by CVE-2025-26330.
What type of vulnerability is CVE-2025-26330?
CVE-2025-26330 is an incorrect authorization vulnerability allowing potential exploitation by unauthenticated attackers.
What can an attacker do with CVE-2025-26330?
An attacker can potentially access the cluster with the privileges of a disabled user account due to CVE-2025-26330.