CVE-2025-26330

Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an incorrect authorization vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability to access the cluster with previous privileges of a disabled user account.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:dell:powerscale_onefs:*:*:*:*:*:*:*:*

History

15 Jul 2025, 16:15

Type Values Removed Values Added
CPE cpe:2.3:a:dell:powerscale_onefs:*:*:*:*:*:*:*:*
First Time Dell
Dell powerscale Onefs
References () https://www.dell.com/support/kbdoc/en-us/000300860/dsa-2025-119-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000300860/dsa-2025-119-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities - Vendor Advisory

10 Apr 2025, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-10 03:15

Updated : 2025-07-15 16:15


NVD link : CVE-2025-26330

Mitre link : CVE-2025-26330


JSON object : View

Products Affected

dell

  • powerscale_onefs
CWE
CWE-863

Incorrect Authorization