CVE-2026-70425: OS Command Injection
Dell PowerScale OneFS, Versions 9.5.0.0 through 9.7.1.0, Versions 9.8.0.0 through 9.10.1.0, and Versions 9.11.0.0 through 9.14.0.1, contain a command injection vulnerability. An admin privileged local attacker could potentially exploit this vulnerability, leading to elevation of privileges to root, impacting confidentiality, integrity, and availability.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
Exploitation requires an attacker with admin-level privileges and local access to the affected Dell PowerScale OneFS system. The vulnerability is not described as remotely exploitable or requiring user interaction.
What is the potential impact of successful exploitation?
A successful command injection could allow the local admin-privileged attacker to elevate privileges to root. This can affect the confidentiality, integrity, and availability of the system.
Which OneFS releases are affected?
Affected releases are 9.5.0.0 through 9.7.1.0, 9.8.0.0 through 9.10.1.0, and 9.11.0.0 through 9.14.0.1.