← All Advisories

Dell Virtual Storage Integrator for VMware vSphere Client IAPI Component Accepts Unauthenticated Remote Input and Passes It to the OS Shell, Enabling Arbitrary Command Execution on the Application Host

Last refreshed2026-09-28

Status: UPDATED  |  Advisory ID: CVE-2026-67261

Key Details

CVECVE-2026-67261
CVSS Score / Version9.8 (Critical) / CVSS v3.1
Updated2026-08-07
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsdell virtual_storage_integrator
Classified asCWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
dellvirtual_storage_integrator
SubsystemsGeneral OT
SectorsMultiple

What to Know

Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying operating system with root privileges. Exploitation may lead to a complete system takeover by an attacker. This vulnerability is considered critical as it allows an unauthenticated remote attacker to achieve arbitrary code execution as root, potentially compromising the entire VSI deployment and underlying infrastructure. Dell recommends customers to upgrade at the earliest opportunity. (NVD)

What to Do

Monitor dell's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-67261
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-67261
Vendor advisoryhttps://www.dell.com/support/kbdoc/en-us/000496035/dsa-2026-335-security-update-for-dell-virtual-storage-integrator-for-vmware-vsphere-client-multiple-vulnerabilities