CVE-2026-35065 PUBLISHED

Assigner: dell
Reserved: 01.04.2026 Published: 17.06.2026 Updated: 17.06.2026

Dell PowerFlex Manager, version(s) [Versions], contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Code execution, Denial of service, Information disclosure, Information tampering, Remote execution, Script injection, and Unauthorized access.

Metrics

CVSS Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 8.8

Product Status

Vendor Dell
Product PowerFlex
Versions Default: unaffected
  • affected from 0 to 5.1.0.1 or later (excl.)
  • affected from 0 to 4.5.5.2 or later (excl.)

Credits

  • Dell would like to thank brocked200 for reporting this issue. other

References

Problem Types

  • CWE-306: Missing Authentication for Critical Function CWE