Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains a use of hard-coded credentials vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to filesystem access for attacker.
References
Configurations
Configuration 1 (hide)
|
History
12 May 2026, 17:19
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:dell:objectscale:*:*:*:*:*:*:*:* cpe:2.3:a:dell:elastic_cloud_storage:*:*:*:*:*:*:*:* |
|
| References | () https://www.dell.com/support/kbdoc/en-us/000462117/dsa-2026-047-security-update-for-dell-ecs-and-objectscale-multiple-vulnerabilities-1 - Vendor Advisory | |
| First Time |
Dell
Dell elastic Cloud Storage Dell objectscale |
11 May 2026, 10:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-11 10:16
Updated : 2026-05-12 17:19
NVD link : CVE-2026-40636
Mitre link : CVE-2026-40636
CVE.ORG link : CVE-2026-40636
JSON object : View
Products Affected
dell
- elastic_cloud_storage
- objectscale
CWE
CWE-798
Use of Hard-coded Credentials
