CVE-2026-35157: Critical severity Dell ECS vulnerability
Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an improper neutralization of formula elements in a CSV File vulnerability in the UI. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35157?
CVE-2026-35157 is considered a high-severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2026-35157?
To fix CVE-2026-35157, upgrade Dell ECS to version 3.8.1.8 or later, and Dell ObjectScale to version 4.3.0.0 or later.
Who is affected by CVE-2026-35157?
CVE-2026-35157 affects users of Dell ECS versions 3.8.1.0 to 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0.
What types of attacks can be executed using CVE-2026-35157?
An attacker exploiting CVE-2026-35157 could execute arbitrary code remotely through improper neutralization of CSV file elements.
Is authentication required to exploit CVE-2026-35157?
No, authentication is not required to exploit CVE-2026-35157, making it particularly dangerous for affected users.