CVE-2026-70425 PUBLISHED

Assigner: dell
Reserved: 04.08.2026 Published: 09.09.2026 Updated: 09.09.2026

Dell PowerScale OneFS, Versions 9.5.0.0 through 9.7.1.0, Versions 9.8.0.0 through 9.10.1.0, and Versions 9.11.0.0 through 9.14.0.1, contain a command injection vulnerability. An admin privileged local attacker could potentially exploit this vulnerability, leading to elevation of privileges to root, impacting confidentiality, integrity, and availability.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 6.7

Product Status

Vendor Dell
Product PowerScale OneFS
Versions Default: unaffected
  • affected from 0 to 9.13.1.1 or later (excl.)
  • affected from 0 to 9.15.0.0 or later (excl.)

Credits

  • Dell would like to thank WinD39 - Huynh Dinh Vu for reporting this issue. other

References

Problem Types

  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE