Dell published a critical security bulletin, addressing multiple Dell ObjectScale vulnerabilities. The vendor warned that “Dell ObjectScale remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.”
Track every CVE that hits your stack the moment it's exploited.
Get free email alertsTL;DR
Dell resolved five security flaws impacting its enterprise object storage software. Most notably, the update fixes an unauthenticated remote code execution flaw that earned a maximum CVSS rating. Organizations should schedule an operating environment upgrade immediately to safeguard their storage clusters.
Why This Threat Matters
Industry estimates show that over two thousand enterprise organizations rely on Dell ObjectScale and ECS storage architectures. Consequently, these critical Dell ObjectScale vulnerabilities introduce severe operational risks to high-capacity storage environments. Threat actors who breach object storage can tamper with confidential backups and exfiltrate proprietary data. Furthermore, attackers can disrupt storage access for critical cloud applications across entire enterprise networks.
How the Attack Works
The most severe issue, CVE-2026-70416 (CVSS 10), stems from insecure deserialization of untrusted data. The advisory warns, “An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.”
Additionally, attackers can exploit CVE-2025-43936 through improper authentication checks to gain unauthorized remote access. Meanwhile, CVE-2026-26947 enables high-privileged local attackers to elevate privileges through improper permission handling. In addition, CVE-2025-36591 exposes sensitive information through broken cryptographic algorithms. Finally, CVE-2026-76104 allows remote administrators to trigger denial of service conditions by altering critical resource permissions.
Affected Versions
These vulnerabilities impact all Dell ObjectScale software releases prior to version 4.4.0.0. Furthermore, the issues affect Dell Elastic Cloud Storage versions 3.x through 3.8.1.7. Currently, security researchers have observed no active in-the-wild exploitation. Likewise, no public proof-of-concept exploits currently exist.
Patch and Mitigation Steps
Storage administrators must upgrade affected deployments to version 4.4.0.0 or later immediately. Alternatively, customers on supported release trains may upgrade directly to version 4.2.0.1. Administrators can request updates by reviewing the Dell security update for ObjectScale. Meanwhile, teams should isolate storage management interfaces behind trusted network firewalls to reduce remote exposure.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!