CVE-2026-32657 PUBLISHED

Assigner: dell
Reserved: 12.03.2026 Published: 18.08.2026 Updated: 19.08.2026

Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell PowerMax Version 10.3.0, Dell Unity Version 5.4, Dell PowerFlex Manager Version 4.5.4, Dell PowerFlex Intelligent Catalog Versions 46.377.00 and 46.382.00 and Dell PowerFlex Rack version 4.5.4 and prior versions, contain(s) an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS Score: 7.3

Product Status

Vendor Dell
Product AppSync
Versions Default: unaffected
  • affected from 0 to 4.6.0.4 or later (excl.)
Vendor Dell
Product Metro Node
Versions Default: unaffected
  • affected from 0 to 4.6.0.4 or later (excl.)
Vendor Dell
Product UCC Edge
Versions Default: unaffected
  • affected from 0 to 3.0.2 or later (excl.)
Vendor Dell
Product VxRail
Versions Default: unaffected
  • affected from 0 to 8.0.330 or later (excl.)
Vendor Dell
Product PowerMax
Versions Default: unaffected
  • affected from 0 to 10.3.1.0 Patch 11248 or later (excl.)
Vendor Dell
Product Unity
Versions Default: unaffected
  • affected from 0 to 5.5.2 or later (excl.)
Vendor Dell
Product PowerFlex Manager
Versions Default: unaffected
  • affected from 0 to 4.5.5 or later (excl.)
Vendor Dell
Product PowerFlex Intelligent Catalog
Versions Default: unaffected
  • affected from 0 to 48.383.00 or later (excl.)
Vendor Dell
Product PowerFlex Intelligent Catalog
Versions Default: unaffected
  • affected from 0 to 48.378.00 or later (excl.)
Vendor Dell
Product PowerFlex Rack
Versions Default: unaffected
  • affected from 0 to 4.5.5 or later (excl.)

References

Problem Types

  • CWE-61: UNIX Symbolic Link (Symlink) Following CWE