CVE-2026-35070

Dell SmartFabric Storage Software, versions prior to 1.4.5, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dell:smartfabric_storage_software:*:*:*:*:*:*:*:*

History

24 Jul 2026, 10:10

Type Values Removed Values Added
Summary
  • (es) Dell SmartFabric Storage Software, versiones anteriores a la 1.4.5, contiene una vulnerabilidad de Neutralización Incorrecta de Elementos Especiales utilizados en un Comando ('Inyección de Comandos'). Un atacante con altos privilegios y acceso local podría potencialmente explotar esta vulnerabilidad, lo que podría llevar a acceso al sistema de archivos para el atacante.

22 May 2026, 19:14

Type Values Removed Values Added
References () https://www.dell.com/support/kbdoc/en-us/000466942/dsa-2026-235-security-update-for-dell-networking-smartfabric-storage-software-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000466942/dsa-2026-235-security-update-for-dell-networking-smartfabric-storage-software-vulnerabilities - Vendor Advisory
First Time Dell smartfabric Storage Software
Dell
CPE cpe:2.3:a:dell:smartfabric_storage_software:*:*:*:*:*:*:*:*

20 May 2026, 10:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-20 10:16

Updated : 2026-07-24 10:10


NVD link : CVE-2026-35070

Mitre link : CVE-2026-35070

CVE.ORG link : CVE-2026-35070


JSON object : View

Products Affected

dell

  • smartfabric_storage_software
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')