Critical Dell ObjectScale flaw allows full system compromise
Key Takeaways Dell Technologies has issued a critical security advisory addressing multiple vulnerabilities in its ObjectScale and Elastic Cloud Storage (ECS) products. The most severe flaw,...
Key Takeaways
- Dell Technologies has issued a critical security advisory addressing multiple vulnerabilities in its ObjectScale and Elastic Cloud Storage (ECS) products.
- The most severe flaw, CVE-2026-70416, is an unauthenticated remote code execution vulnerability in Dell ObjectScale, scoring a perfect 10.0 on the CVSS scale.
- Successful exploitation of this critical flaw could lead to full system compromise, data access, and disruption of storage operations.
- Patches are available, with Dell recommending upgrades to ObjectScale/ECS version 4.4.0.0 or later.
Dell Technologies has disclosed a series of significant security vulnerabilities impacting its Dell ObjectScale and Elastic Cloud Storage (ECS) deployments. The advisory, identified as DSA-2026-393 and published on September 10, 2026, highlights several flaws, including a critical remote code execution vulnerability that could allow an unauthenticated attacker to fully compromise affected systems.
Table Of Content
Critical Remote Code Execution Threat
The most severe vulnerability identified is CVE-2026-70416, a critical untrusted-data deserialization flaw affecting Dell ObjectScale versions prior to 4.4.0.0. This vulnerability has been assigned the maximum CVSS score of 10.0, indicating its extreme severity. An unauthenticated remote attacker could exploit this flaw to execute arbitrary code on a vulnerable system.
A successful attack could grant the perpetrator complete control over the ObjectScale environment. This level of access would enable them to retrieve sensitive data, modify system configurations, disrupt crucial storage services, inject malicious payloads, and establish persistent access within the compromised infrastructure. Given ObjectScale’s role in providing enterprise-grade object storage for backups, application data, archives, and cloud-native workloads, a compromise could have profound implications for organizations relying on the platform.
Additional Vulnerabilities Detailed
The security advisory also details several other vulnerabilities:
- CVE-2025-43936: Improper Authentication (CVSS 8.1)
This flaw affects ObjectScale versions before 4.4.0.0. Despite a high attack complexity, it allows an unauthenticated remote attacker to gain unauthorized access without requiring credentials or user interaction. Dell emphasizes the importance of limiting network exposure to mitigate this risk. - CVE-2026-26947: Improper Privilege Management (CVSS 6.7)
Affecting both Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions earlier than 4.4.0.0, this vulnerability could be exploited by a local attacker with high privileges to further escalate their access, impacting confidentiality, integrity, and availability. - CVE-2025-36591: Broken or Risky Cryptographic Algorithm (CVSS 4.4)
Also affecting the aforementioned ECS and ObjectScale versions, this issue could allow a high-privileged local attacker to expose sensitive information. - CVE-2026-76104: Incorrect Permission Assignment (CVSS 5.5)
This operating system-level vulnerability could enable a high-privileged remote attacker to trigger denial-of-service conditions.
Furthermore, the advisory lists several vulnerabilities in third-party components, including Apache Log4j, liblzma, and the Linux kernel. These encompass CVE-2026-34477, CVE-2026-34478, CVE-2026-34480, CVE-2026-34743, CVE-2026-31694, and CVE-2026-43499.
Security researcher WinD39, also known as Huynh Dinh Vu, was credited by Dell for reporting CVE-2026-70416.
What You Should Do
- Apply Updates Immediately: Dell strongly recommends that customers upgrade their affected ObjectScale and ECS systems to version 4.4.0.0 or later as soon as possible. Customers on supported affected releases may also upgrade directly to version 4.2.0.1.
- Initiate Service Requests: Organizations should open an Operating Environment Upgrade service request and reference DSA-2026-393 to facilitate the update process.
- Implement Secure Service-Level Communication: As an interim mitigation for CVE-2025-43936, consult the Secure Service-Level Communication guidance within the official Security Configuration Guide.
- Restrict Network Access: Limit administrative and storage-management interfaces to trusted networks only.
- Monitor for Anomalies: Regularly review exposed ObjectScale services, monitor for any abnormal authentication activity, and investigate unexpected configuration or permission changes.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.