CVE-2026-46460: Low severity Dell PowerScale OneFS vulnerability
Dell PowerScale OneFS, versions 9.5.0.0 through 9.7.1.15, versions 9.8.0.0 through 9.13.1.0, and versions prior to 9.15.0.0, contain an Incorrect Authorization vulnerability. A low privileged adjacent network attacker could potentially exploit this vulnerability, leading to unauthorized modification of system logs.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access between the adjacent/low-privileged network and the Dell PowerScale OneFS management/logging interfaces to trusted sources only, to reduce the ability of an adjacent network attacker to exploit the Incorrect Authorization vulnerability.
Event History
Frequently Asked Questions
Who can realistically exploit this issue?
An attacker must already have low-privileged access and be on an adjacent network. The issue does not describe exploitation by an unauthenticated remote internet attacker.
What is the practical impact if exploitation succeeds?
Successful exploitation could allow unauthorized modification of system logs. The provided severity vector indicates integrity impact only; no confidentiality or availability impact is stated.
Which OneFS releases are affected?
Affected releases are 9.5.0.0 through 9.7.1.15, 9.8.0.0 through 9.13.1.0, and releases prior to 9.15.0.0.