CVE-2026-54489 PUBLISHED

Assigner: dell
Reserved: 15.06.2026 Published: 06.08.2026 Updated: 06.08.2026

Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session hijacking. This vulnerability is considered critical as it allows an unauthenticated attacker to obtain active session credentials and fully impersonate authenticated users, including administrators. Dell recommends customers to upgrade at the earliest opportunity.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS Score: 9.1

Product Status

Vendor Dell
Product Virtual Storage Integrator for VMware vSphere Client
Versions Default: unaffected
  • affected from 0 to 10.11.1.0 or later (excl.)

Credits

  • Dell would like to be thanking for reporting CVE-2026-54489 kkking other

References

Problem Types

  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE