Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-79686

CVE-2026-79686: Dell PowerStore Privilege Escalation Flaw

CVE-2026-79686 is a privilege escalation vulnerability in Dell PowerStore that allows authenticated users with limited privileges to bypass access controls and gain elevated permissions. This article covers technical details, affected versions, security impact, and mitigation strategies.

Published:

CVE-2026-79686 Overview

CVE-2026-79686 is a Protection Mechanism Failure vulnerability [CWE-693] affecting Dell PowerStore. An authenticated user with limited privileges can bypass access restrictions and gain escalated privileges on the storage platform. Dell disclosed the flaw in security advisory DSA-2026-330, covering PowerStore T series products.

Successful exploitation compromises confidentiality, integrity, and availability of managed storage. Because PowerStore hosts enterprise data assets, privilege escalation on these appliances exposes production workloads to tampering and data theft.

Critical Impact

An authenticated low-privileged attacker on the network can escalate to administrative access on PowerStore appliances, gaining full control over stored data and appliance configuration.

Affected Products

  • Dell PowerStore T series (see DSA-2026-330 for exact affected versions)
  • Dell PowerStore management interface components
  • Dell PowerStore OS releases prior to the fixed build referenced in the Dell advisory

Discovery Timeline

  • 2026-09-01 - CVE-2026-79686 published to the National Vulnerability Database (NVD)
  • 2026-09-02 - Last updated in NVD database

Technical Details for CVE-2026-79686

Vulnerability Analysis

CVE-2026-79686 is categorized as a Protection Mechanism Failure [CWE-693]. The flaw indicates that a security control intended to enforce authorization on PowerStore is either missing, insufficient, or reachable through an unintended path. An attacker who already holds valid, low-privileged credentials on the appliance can invoke functionality reserved for higher-privileged roles.

The CWE-693 class typically covers cases where checks exist but do not cover all code paths, where checks can be bypassed by manipulating request parameters, or where role boundaries are enforced inconsistently between the user interface and backend APIs. Dell has not published exploitation specifics beyond the advisory DSA-2026-330.

Impact spans all three security properties. A promoted account can read arbitrary volumes and snapshots, alter storage configuration, modify replication or protection policies, and disrupt service. On multi-tenant deployments, tenant isolation on the appliance cannot be assumed once this bypass succeeds.

Root Cause

The root cause is a failure of the authorization protection mechanism on PowerStore. Refer to the Dell Security Update Advisory for vendor-supplied details on the affected component and the corrected logic.

Attack Vector

The attack is network-reachable and requires authentication with limited privileges. No user interaction is required, and the attack complexity is low. An attacker sends crafted requests to the PowerStore management surface from any host that can reach it, then exercises functions that should be gated behind an administrator role.

No public proof-of-concept or exploit code is available at time of publication. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog.

Detection Methods for CVE-2026-79686

Indicators of Compromise

  • Authenticated PowerStore sessions where a low-privileged account invokes administrative REST or CLI endpoints
  • Configuration changes (user creation, role assignment, replication policy edits) originating from non-administrator accounts
  • Unexpected volume, snapshot, or export changes correlated with limited-privilege session tokens
  • Audit log gaps or entries missing the expected role attribution for privileged operations

Detection Strategies

  • Baseline the set of accounts permitted to call administrative PowerStore APIs and alert on deviations
  • Correlate PowerStore audit events with identity provider logs to detect role mismatches between authentication and action
  • Hunt for repeated authorization failures immediately followed by successful privileged calls from the same session

Monitoring Recommendations

  • Forward PowerStore audit and management logs to a centralized SIEM or data lake with OCSF normalization
  • Enable alerting on user, role, and RBAC configuration changes on all PowerStore appliances
  • Restrict management-network reachability and monitor north-south traffic to the PowerStore management IPs

How to Mitigate CVE-2026-79686

Immediate Actions Required

  • Apply the Dell PowerStore update referenced in advisory DSA-2026-330 on all affected appliances
  • Inventory all PowerStore T deployments and confirm current PowerStoreOS build against the fixed version
  • Rotate credentials for low-privileged PowerStore accounts and review recent administrative activity
  • Restrict the PowerStore management network to a dedicated administrative VLAN with strict access controls

Patch Information

Dell released fixed PowerStore builds as part of security advisory DSA-2026-330. Consult the Dell Security Update Advisory for exact fixed versions, upgrade procedures, and any prerequisite firmware levels. Apply the vendor patch as the primary remediation.

Workarounds

  • Limit PowerStore management interface exposure to a hardened jump host or bastion segment
  • Enforce least privilege on all PowerStore local and directory-integrated accounts and remove unused low-privileged accounts
  • Enable multi-factor authentication on identity providers fronting PowerStore administrative access where supported
  • Increase audit log retention and forward logs off-appliance so tampering after escalation can be detected

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.