CVE-2026-70416: Critical severity Dell ObjectScale vulnerability
Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell ObjectScaleto a version that resolves this vulnerability.Fixed in 4.4.0.0
Event History
Frequently Asked Questions
Which deployments are exposed?
Dell ObjectScale versions earlier than 4.4.0.0 are affected. The issue is remotely reachable and does not require authentication.
What does an attacker need to exploit this issue?
An attacker needs remote access to the affected Dell ObjectScale instance. No privileges or user interaction are required.
What is the potential impact of successful exploitation?
Successful exploitation could lead to remote code execution. The provided severity vector indicates high potential impact to confidentiality, integrity, and availability.
How can I determine whether remediation is needed?
Check the installed Dell ObjectScale version. Systems running a version prior to 4.4.0.0 require remediation.