CVE-2026-35069

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Script injection.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:powerflex_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:powerflex_manager:*:*:*:*:*:*:*:*

History

25 Jun 2026, 14:16

Type Values Removed Values Added
Summary (en) Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Script injection. (en) Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Script injection.

22 Jun 2026, 18:30

Type Values Removed Values Added
First Time Dell powerflex Manager
Dell
CPE cpe:2.3:a:dell:powerflex_manager:*:*:*:*:*:*:*:*
References () https://www.dell.com/support/kbdoc/en-us/000477538/dsa-2026-066-security-update-for-powerflex-software-multiple-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000477538/dsa-2026-066-security-update-for-powerflex-software-multiple-vulnerabilities - Vendor Advisory

17 Jun 2026, 20:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-17 17:16

Updated : 2026-06-25 14:16


NVD link : CVE-2026-35069

Mitre link : CVE-2026-35069

CVE.ORG link : CVE-2026-35069


JSON object : View

Products Affected

dell

  • powerflex_manager
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')