← All Advisories

CVE-2026-58572

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-58572

Key Details

CVECVE-2026-58572
CVSS Score / Version8.8 (High) / CVSS v3.1
Updated2026-10-02
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productssee table below
Classified asCWE-94 (Improper Control of Generation of Code ('Code Injection'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
dellpowerstoreos
dellPowerStore 500T
dellPowerStore 1000T
dellPowerStore 1200T
dellPowerStore 3000T
dellPowerStore 3200Q
dellPowerStore 3200T
dellPowerStore 5000T
dellPowerStore 5200Q
dellPowerStore 5200T
dellPowerStore 7000T
dellPowerStore 9000T
dellPowerStore 9200T
SubsystemsGeneral OT
SectorsMultiple

What to Know

Dell PowerStore contains a Code Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary code with root privileges. (NVD)

What to Do

Monitor dell's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-58572
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-58572
Vendor advisoryhttps://www.dell.com/support/kbdoc/en-us/000497829/dsa-2026-330-dell-powerstore-t-security-update-for-multiple-vulnerabilities