TL;DR
Dell patched two critical flaws in Virtual Storage Integrator (VSI) for VMware vSphere Client. The worst, CVE-2026-67261, allows unauthenticated remote code execution as root, scoring CVSS 9.8. A second bug, CVE-2026-54489, enables session hijacking at CVSS 9.1. No exploitation in the wild has been confirmed.
- Product: Dell Virtual Storage Integrator for VMware vSphere Client
- Vulnerabilities: 2 flaws (CVE-2026-67261, CVE-2026-54489)
- Highest severity: 9.8 (Critical · CVSSv3)
- Worst impact: Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s...
- Status: No confirmed exploitation yet; patches available
- Action: Update to 10.11.1.0 or later now
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-67261 | 9.8 | CWE-78 | 10.11.1.0 or later | Not exploited |
| CVE-2026-54489 | 9.1 | CWE-200 | 10.11.1.0 or later | Not exploited |
Why This Matters
VSI plugs directly into the VMware vSphere Client. A single unauthenticated attacker can therefore reach the plugin over the network. Successful exploitation of CVE-2026-67261 hands the attacker root on the host. As Dell warns, “Exploitation may lead to a complete system takeover by an attacker.”
How the Attack Works
The critical flaw is an OS command injection bug in the IAPI component. According to Dell, the product versions prior to 10.11.1.0 “contain(s) an OS Command Injection vulnerability in the IAPI component.” As a result, a remote unauthenticated attacker can run arbitrary OS commands with root privileges.
The second issue is a sensitive information disclosure flaw. Dell notes it “allows an unauthenticated attacker to obtain active session credentials and fully impersonate authenticated users, including administrators.” Together, these bugs threaten the entire VSI deployment.
Affected Versions
Both vulnerabilities affect Dell Virtual Storage Integrator for VMware vSphere Client in all versions prior to 10.11.1.0.
Patch and Mitigation
Dell fixed both flaws in version 10.11.1.0 and later. The vendor “recommends customers to upgrade at the earliest opportunity.” Admins should review the official DSA-2026-335 advisory from Dell and apply the update without delay. No workaround exists, so upgrading is the only fix.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.