CVE-2026-32657: High severity Dell AppSync vulnerability
Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell PowerMax Version 10.3.0, Dell Unity Version 5.4, Dell PowerFlex Manager Version 4.5.4, Dell PowerFlex Intelligent Catalog Versions 46.377.00 and 46.382.00 and Dell PowerFlex Rack version 4.5.4 and prior versions, contain(s) an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Affected Software
Event History
Frequently Asked Questions
Who is realistically exposed?
Exposure is limited to systems running one of the listed Dell products and versions, including Dell PowerFlex Rack 4.5.4 and earlier. The provided data does not identify any network-reachable attack path.
What does an attacker need to exploit this issue?
An attacker needs local access, low-privileged credentials or execution capability, and user interaction. Successful exploitation could elevate privileges and affect confidentiality, integrity, and availability.
Is a default installation known to be affected?
The affected versions are explicitly identified, but the data does not state whether the vulnerable symlink handling is enabled or reachable in a default configuration.
How can I determine whether my environment is affected?
Compare deployed product versions against the affected versions listed in the advisory. The supplied information does not provide indicators of compromise or other detection guidance.