Dell ObjectScale Vulnerabilities Hit CVSS 10.0

Published September 11, 2026 CVE-2026-70416

Dell ObjectScale has a critical flaw that could let an unauthenticated remote attacker execute code. Dell rates it 10.0, the highest CVSS severity.

Severity
CriticalCVSS 3.1 · 10.0 · dell.com
Fix
Fixed in 4.4.0.0
Exploited
Not confirmedNo confirmation recorded

How it works

  • CVE-2026-70416 involves ObjectScale processing untrusted data.
  • An unauthenticated attacker with remote access could potentially exploit this flaw.
  • Dell says exploitation could lead to remote execution.

What to do

Check the ObjectScale version in each storage environment. versions older than 4.4.0.0 are within Dell's affected range.

Open a Dell Operating Environment Upgrade service request and upgrade to ObjectScale 4.4.0.0 or later. Customers on supported affected releases may also upgrade directly to 4.2.0.1.

Technical details

CVE-2026-70416 is an unauthenticated remote-execution flaw in Dell ObjectScale versions older than 4.4.0.0. Dell assigns it CVSS 10.0, with network access required but no login or user interaction.

Severity breakdown

  • Attack vector Network Requires network access to the vulnerable service
  • Attack complexity Low Low complexity under the assessed conditions
  • Privileges required None Attacker needs no account or login
  • User interaction None No victim action needed
  • Scope Changed Impact crosses a security authority boundary
  • Confidentiality impact High Sensitive data can be exposed with serious impact
  • Integrity impact High Protected data can be changed with serious impact
  • Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Open in FIRST.org calculator