CVE-2025-26330

HIGH

Dell PowerScale OneFS 9.4.0-9.10.0.1 - Unauthenticated Incorrect Authorization

Title source: llm
STIX 2.1

Description

Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an incorrect authorization vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability to access the cluster with previous privileges of a disabled user account.

Scores

CVSS v3 7.0
EPSS 0.0021
EPSS Percentile 42.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-863
Status published
Products (1)
dell/powerscale_onefs 9.4.0 - 9.10.1.1
Published Apr 10, 2025
Tracked Since Feb 18, 2026