Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-35066

CVE-2026-35066: Dell PowerFlex Manager DoS Vulnerability

CVE-2026-35066 is a denial of service vulnerability in Dell PowerFlex Manager caused by improper access control. Low-privileged attackers can exploit this remotely. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-35066 Overview

CVE-2026-35066 is an Improper Access Control vulnerability [CWE-284] affecting Dell PowerFlex Manager. The flaw enables a low-privileged attacker with remote network access to trigger a denial of service condition against the management software. Dell published advisory DSA-2026-066 describing this issue alongside other PowerFlex software vulnerabilities.

The CVSS vector indicates network-reachable exploitation with low attack complexity and no user interaction. Successful exploitation impacts availability while producing limited integrity effects and no confidentiality loss. The EPSS probability is 0.183%, placing it in the 8.031 percentile for likelihood of near-term exploitation.

Critical Impact

An authenticated low-privileged remote attacker can disrupt Dell PowerFlex Manager availability, affecting management of PowerFlex storage infrastructure.

Affected Products

  • Dell PowerFlex Manager (specific versions identified in Dell advisory DSA-2026-066)
  • Dell PowerFlex software ecosystem components referenced in the same advisory

Discovery Timeline

  • 2026-06-17 - CVE-2026-35066 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2026-35066

Vulnerability Analysis

Dell PowerFlex Manager fails to enforce proper access control on functionality reachable by authenticated low-privileged users. The condition is classified under [CWE-284] Improper Access Control. An attacker with valid but limited credentials can reach functionality that should be restricted to higher-privileged roles.

The outcome of the access control failure is a denial of service against the PowerFlex Manager component. Because PowerFlex Manager orchestrates and monitors PowerFlex software-defined storage, disruption of the management plane affects administrative operations across the storage environment.

The CVSS scope is unchanged, meaning impact remains within the vulnerable component. Confidentiality is not affected, integrity sees limited impact, and availability sees high impact. This pattern is consistent with an authorization gap that allows a user to invoke a function that exhausts a resource or terminates a service.

Root Cause

The root cause is missing or insufficient authorization checks on a code path in Dell PowerFlex Manager. Functionality intended for privileged administrators is accessible to lower-privileged accounts. Dell has not published exploit-level technical detail beyond the advisory.

Attack Vector

The attack vector is network-based. An attacker authenticates with a low-privileged account, then issues a request to the exposed PowerFlex Manager interface. The request reaches the improperly protected functionality and causes service disruption. No user interaction is required, and attack complexity is low. Refer to the Dell Security Update DSA-2026-066 for vendor-supplied technical guidance.

Detection Methods for CVE-2026-35066

Indicators of Compromise

  • Unexpected restarts, hangs, or unresponsive states in Dell PowerFlex Manager services following requests from non-administrator accounts
  • Authentication events from low-privileged PowerFlex Manager accounts immediately preceding service availability loss
  • Anomalous API or web request patterns from accounts that do not typically perform administrative actions

Detection Strategies

  • Correlate PowerFlex Manager service health telemetry with authentication and API access logs to identify low-privileged actors triggering availability events
  • Baseline normal request patterns per role and alert on low-privileged accounts invoking endpoints historically used only by administrators
  • Track repeated failed or unusual administrative operations originating from standard user sessions

Monitoring Recommendations

  • Forward PowerFlex Manager application, authentication, and audit logs to a centralized analytics platform for retention and correlation
  • Monitor process and service availability of PowerFlex Manager components with alerting on restart loops or crash signatures
  • Review role-based access control assignments periodically to confirm that low-privileged accounts cannot reach sensitive functionality

How to Mitigate CVE-2026-35066

Immediate Actions Required

  • Apply the fixed PowerFlex Manager release identified in Dell advisory DSA-2026-066 as soon as feasible
  • Inventory PowerFlex Manager instances and confirm version exposure against the advisory
  • Restrict network reachability of PowerFlex Manager to administrative networks and jump hosts only
  • Review and reduce the number of low-privileged accounts with access to PowerFlex Manager

Patch Information

Dell has released fixed versions through advisory Dell Security Update DSA-2026-066. Administrators should consult the advisory for the exact remediated versions and upgrade paths applicable to their deployment.

Workarounds

  • Limit PowerFlex Manager network exposure using firewall rules and network segmentation until the patch is applied
  • Enforce least privilege by removing PowerFlex Manager access from accounts that do not require it
  • Require multi-factor authentication for all PowerFlex Manager logins to reduce risk from credential compromise
  • Monitor service health and authentication logs closely until remediation is verified

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.