Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-76111

CVE-2026-76111: Dell PowerStore Privilege Escalation Flaw

CVE-2026-76111 is a privilege escalation vulnerability in Dell PowerStore that allows low-privileged users to execute admin-only operations. This article covers the technical details, security impact, and steps to protect your systems.

Published:

CVE-2026-76111 Overview

Dell PowerStore contains an Incorrect Authorization vulnerability [CWE-863] that allows an authenticated low-privileged attacker to invoke administrator-only operations. Successful exploitation results in privilege escalation, granting the attacker control over storage management functions typically reserved for administrators. The flaw is network-exploitable and requires only low-level credentials, making it accessible to any authenticated user of the PowerStore management interface. Dell published advisory DSA-2026-330 to address this and other vulnerabilities affecting PowerStore T systems.

Critical Impact

An authenticated low-privileged user can invoke administrator-only operations on Dell PowerStore, resulting in full privilege escalation and compromise of storage confidentiality, integrity, and availability.

Affected Products

  • Dell PowerStore T
  • Refer to Dell Security Advisory DSA-2026-330 for the complete list of affected versions
  • Related PowerStore management components covered in the advisory

Discovery Timeline

  • 2026-09-01 - CVE-2026-76111 published to the National Vulnerability Database
  • 2026-09-02 - Last updated in NVD database

Technical Details for CVE-2026-76111

Vulnerability Analysis

The vulnerability is an authorization enforcement flaw in Dell PowerStore. The management layer authenticates the requester but fails to verify that the account holds the privileges required for administrator-only operations. As a result, standard user roles can invoke functions intended for administrators, bypassing the platform's role-based access control model.

Exploitation requires valid credentials to the PowerStore management interface. Once authenticated, an attacker issues requests to privileged endpoints or operations that the authorization layer should reject. Successful exploitation compromises storage configuration, data confidentiality, integrity, and system availability.

An EPSS score of 0.286% places CVE-2026-76111 in the 20.73 percentile, indicating a lower predicted likelihood of near-term exploitation. No public exploit code and no CISA KEV listing exist at the time of publication.

Root Cause

The root cause is missing or incomplete authorization checks on privileged operations, classified as CWE-863 Incorrect Authorization. The application logic verifies the identity of the caller but does not enforce the role or permission required to execute administrator-scoped actions. This design gap allows any authenticated user to reach protected functions.

Attack Vector

The attack vector is network-based and requires low-privileged authentication. An attacker with any valid PowerStore account credentials submits crafted requests to administrator-only management functions. No user interaction is needed, and the attack does not require elevated existing privileges. See the Dell Security Advisory DSA-2026-330 for endpoint-level technical details.

Detection Methods for CVE-2026-76111

Indicators of Compromise

  • Management API calls to administrator-only endpoints originating from accounts with non-administrator roles
  • Unexpected configuration changes, user account creations, or role modifications performed by low-privileged users
  • Audit log entries showing privileged operations attributed to accounts without administrator assignment
  • Repeated authorization-related errors followed by successful privileged actions from the same session

Detection Strategies

  • Correlate PowerStore audit logs against the authenticated user's assigned role and flag privileged operations performed by non-administrator accounts
  • Baseline normal API usage patterns per role and alert on deviations, particularly non-admin accounts invoking administrative endpoints
  • Monitor for anomalous session activity such as sudden bursts of configuration changes from historically read-only accounts

Monitoring Recommendations

  • Forward PowerStore management and audit logs to a centralized SIEM for continuous analysis
  • Enable alerting on role-privilege mismatches and administrative action attempts by standard users
  • Review authentication logs for credential compromise indicators such as impossible-travel logins or password-spray patterns preceding privileged actions

How to Mitigate CVE-2026-76111

Immediate Actions Required

  • Apply the security update referenced in Dell Security Advisory DSA-2026-330 to all affected PowerStore T systems
  • Audit existing PowerStore user accounts and remove or downgrade unnecessary access
  • Rotate credentials for accounts that may have been exposed or shared
  • Restrict network access to the PowerStore management interface to trusted administrative networks only

Patch Information

Dell has released a security update for PowerStore T addressing CVE-2026-76111. Customers should consult the Dell Security Advisory DSA-2026-330 for the fixed version numbers and upgrade procedures. Apply the update as soon as change-management windows permit.

Workarounds

  • Limit PowerStore management interface exposure to a segmented administrative network or jump-host bastion
  • Enforce least-privilege role assignments and remove standing low-privilege accounts that are no longer required
  • Enable multi-factor authentication on identity providers integrated with PowerStore where supported
  • Increase audit log retention and monitoring frequency until the patch is applied

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.