CVE-2026-35070: Command Injection
Dell SmartFabric Storage Software, versions prior to 1.4.5, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell SmartFabric Storage Softwareto a version that resolves this vulnerability.Fixed in 1.4.5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35070?
CVE-2026-35070 is considered a high severity vulnerability due to the potential for an attacker to gain filesystem access.
How do I fix CVE-2026-35070?
To fix CVE-2026-35070, upgrade to Dell SmartFabric Storage Software version 1.4.5 or later.
Who is affected by CVE-2026-35070?
CVE-2026-35070 affects users of Dell SmartFabric Storage Software versions prior to 1.4.5.
What type of vulnerability is CVE-2026-35070?
CVE-2026-35070 involves an Improper Neutralization of Special Elements used in a Command, also known as a command injection vulnerability.
What could an attacker achieve through CVE-2026-35070?
An attacker with local access could exploit CVE-2026-35070 to potentially gain filesystems access.