CVE-2026-28265

PowerStore, contains a Path Traversal vulnerability in the Service user. A low privileged attacker with local access could potentially exploit this vulnerability, leading to modification of arbitrary system files.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dell:powerstoreos:*:*:*:*:*:*:*:*
OR cpe:2.3:h:dell:powerstore_1000t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_1200t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_3000t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_3200q:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_3200t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_5000t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_500t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_5200q:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_5200t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_7000t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_9000t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_9200t:-:*:*:*:*:*:*:*

History

02 Apr 2026, 20:43

Type Values Removed Values Added
First Time Dell powerstore 5000t
Dell powerstore 5200t
Dell powerstore 1000t
Dell powerstoreos
Dell powerstore 3000t
Dell powerstore 9000t
Dell powerstore 5200q
Dell powerstore 9200t
Dell powerstore 3200q
Dell powerstore 7000t
Dell powerstore 3200t
Dell powerstore 500t
Dell powerstore 1200t
Dell
CPE cpe:2.3:h:dell:powerstore_3200q:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_3200t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_3000t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_9200t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_5000t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_9000t:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:powerstoreos:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_5200t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_500t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_1200t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_5200q:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_7000t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_1000t:-:*:*:*:*:*:*:*
References () https://www.dell.com/support/kbdoc/en-us/000444169/dsa-2026-157-dell-powerstore-t-security-update-for-multiple-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000444169/dsa-2026-157-dell-powerstore-t-security-update-for-multiple-vulnerabilities - Vendor Advisory
CWE CWE-22

01 Apr 2026, 08:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-01 08:16

Updated : 2026-04-02 20:43


NVD link : CVE-2026-28265

Mitre link : CVE-2026-28265

CVE.ORG link : CVE-2026-28265


JSON object : View

Products Affected

dell

  • powerstore_5000t
  • powerstore_3200q
  • powerstore_5200t
  • powerstore_1200t
  • powerstore_5200q
  • powerstore_9200t
  • powerstore_7000t
  • powerstore_3200t
  • powerstore_3000t
  • powerstore_500t
  • powerstoreos
  • powerstore_1000t
  • powerstore_9000t
CWE
CWE-35

Path Traversal: '.../...//'

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')