Dell ObjectScale Vulnerabilities Hit CVSS 10.0
Dell ObjectScale has a critical flaw that could let an unauthenticated remote attacker execute code. Dell rates it 10.0, the highest CVSS severity.
- Severity
- CriticalCVSS 3.1 · 10.0 · dell.com
- Fix
- Fixed in 4.4.0.0
- Exploited
- Not confirmedNo confirmation recorded
How it works
- CVE-2026-70416 involves ObjectScale processing untrusted data.
- An unauthenticated attacker with remote access could potentially exploit this flaw.
- Dell says exploitation could lead to remote execution.
What to do
Check the ObjectScale version in each storage environment. versions older than 4.4.0.0 are within Dell's affected range.
Open a Dell Operating Environment Upgrade service request and upgrade to ObjectScale 4.4.0.0 or later. Customers on supported affected releases may also upgrade directly to 4.2.0.1.
Technical details
CVE-2026-70416 is an unauthenticated remote-execution flaw in Dell ObjectScale versions older than 4.4.0.0. Dell assigns it CVSS 10.0, with network access required but no login or user interaction.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required None Attacker needs no account or login
- User interaction None No victim action needed
- Scope Changed Impact crosses a security authority boundary
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact High Protected data can be changed with serious impact
- Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Open in FIRST.org calculator