← All Advisories

CVE-2026-58574

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-58574

Key Details

CVECVE-2026-58574
CVSS Score / Version9.8 (Critical) / CVSS v3.1
Updated2026-10-01
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productssee table below
Classified asCWE-306 (Missing Authentication for Critical Function)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
dellpowerstoreos
dellPowerStore 500T
dellPowerStore 1000T
dellPowerStore 1200T
dellPowerStore 3000T
dellPowerStore 3200Q
dellPowerStore 3200T
dellPowerStore 5000T
dellPowerStore 5200Q
dellPowerStore 5200T
dellPowerStore 7000T
dellPowerStore 9000T
dellPowerStore 9200T
SubsystemsGeneral OT
SectorsMultiple

What to Know

Dell PowerStore contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with network access to the restricted management interface could potentially exploit this vulnerability to read internal system information from the appliance filesystem. This is a Critical vulnerability as it could expose sensitive information and credentials which allow full administrative access to the array. (NVD)

What to Do

Monitor dell's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-58574
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-58574
Vendor advisoryhttps://www.dell.com/support/kbdoc/en-us/000497829/dsa-2026-330-dell-powerstore-t-security-update-for-multiple-vulnerabilities