Threat Advisory

Dell ObjectScale Flaw Lets Attackers Compromise and Execute Code Remotely

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in Dell ObjectScale and Elastic Cloud Storage (ECS) deployments. The most severe issue is a critical untrusted-data deserialization vulnerability, tracked as DSA-2026-393, which affects Dell ObjectScale versions prior to 4.4.0.0. This flaw carries a CVSS score of 10.0 and could allow an unauthenticated remote attacker to execute code on an affected system.

CVE-2026-70416 (CVSS 10.0 — Critical): A critical untrusted-data deserialization vulnerability in Dell ObjectScale versions prior to 4.4.0.0 allows an unauthenticated remote attacker to execute code on an affected system. Successful exploitation could give an attacker control over the ObjectScale environment, enabling them to access data, alter configurations, disrupt storage operations, deploy malicious payloads, or establish persistence in the affected infrastructure.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in Dell ObjectScale and Elastic Cloud Storage (ECS) deployments. The most severe issue is a critical untrusted-data deserialization vulnerability, tracked as DSA-2026-393, which affects Dell ObjectScale versions prior to 4.4.0.0. This flaw carries a CVSS score of 10.0 and could allow an unauthenticated remote attacker to execute code on an affected system.

CVE-2026-70416 (CVSS 10.0 — Critical): A critical untrusted-data deserialization vulnerability in Dell ObjectScale versions prior to 4.4.0.0 allows an unauthenticated remote attacker to execute code on an affected system. Successful exploitation could give an attacker control over the ObjectScale environment, enabling them to access data, alter configurations, disrupt storage operations, deploy malicious payloads, or establish persistence in the affected infrastructure.[emaillocker id="1283"]

CVE-2025-43936 (CVSS 8.1 — High): An improper authentication vulnerability affects Dell ObjectScale versions prior to 4.4.0.0 and may allow an unauthenticated attacker with remote access to gain unauthorized access. Although its attack complexity is rated high, the vulnerability does not require credentials or user interaction.

CVE-2026-26947 (CVSS 6.7 — Medium): An improper privilege management flaw affects both Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.4.0.0. A local attacker with high privileges could exploit it to elevate privileges further and affect confidentiality, integrity, and availability.

CVE-2025-36591 (CVSS 4.4 — Low): A broken or risky cryptographic algorithm vulnerability affects Dell ObjectScale versions prior to 4.4.0.0. A high-privileged local attacker could potentially exploit the issue to expose sensitive information.

CVE-2026-76104 (CVSS 5.5 — Medium): An incorrect permission assignment vulnerability in the operating system affects both Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.4.0.0. A high-privileged remote attacker could exploit it to cause denial-of-service conditions.

Security teams should also restrict administrative and storage-management interfaces to trusted networks, review exposed ObjectScale services, monitor for abnormal authentication activity, and investigate unexpected configuration or permission changes.

RECOMMENDATION:

We recommend you to upgrade Dell ObjectScale to version 4.2.0.1.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu