CVE-2026-35070

Dell SmartFabric Storage Software, versions prior to 1.4.5, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dell:smartfabric_storage_software:*:*:*:*:*:*:*:*

History

22 May 2026, 19:14

Type Values Removed Values Added
First Time Dell smartfabric Storage Software
Dell
CPE cpe:2.3:a:dell:smartfabric_storage_software:*:*:*:*:*:*:*:*
References () https://www.dell.com/support/kbdoc/en-us/000466942/dsa-2026-235-security-update-for-dell-networking-smartfabric-storage-software-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000466942/dsa-2026-235-security-update-for-dell-networking-smartfabric-storage-software-vulnerabilities - Vendor Advisory

20 May 2026, 10:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-20 10:16

Updated : 2026-05-22 19:14


NVD link : CVE-2026-35070

Mitre link : CVE-2026-35070

CVE.ORG link : CVE-2026-35070


JSON object : View

Products Affected

dell

  • smartfabric_storage_software
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')