{"id":"CVE-2026-46460","title":"Dell PowerScale OneFS, versions 9.5.0.0 through 9.7.1.15, versions 9.8.0.0 through 9.13.1.0, and versions prior to 9.15.0.0, contain an Incorrect Authorization vulnerability","summary":"Dell PowerScale OneFS, versions 9.5.0.0 through 9.7.1.15, versions 9.8.0.0 through 9.13.1.0, and versions prior to 9.15.0.0, contain an Incorrect Authorization vulnerability. A low privileged adjacent network attacker could potentially e…","severity":"low","cvss":3.5,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-863"],"vendor":"dell","product":"powerscale_onefs","affected":["powerscale_onefs >= 9.5.0.0, <= 9.7.1.15","powerscale_onefs >= 9.8.0.0, <= 9.13.1.0","powerscale_onefs >= 9.14.0.0, < 9.15.0.0"],"patched":["powerscale_onefs 9.15.0.0"],"published":"2026-09-09","updated":"2026-09-16","sourceUpdated":"2026-09-16T15:30:46.057","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-46460","references":[{"url":"https://www.dell.com/support/kbdoc/en-us/000505684/dsa-2026-360-security-update-for-dell-powerscale-onefs-multiple-vulnerabilities","label":"security_alert@emc.com"}],"tags":["nvd","cve.org"],"epss":0.00185,"epssPercentile":0.0712,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-09T16:52:32.015045Z"},"ingestedAt":"2026-09-12T17:26:02.577Z","slug":"CVE-2026-46460","body":"## Overview\n\nDell PowerScale OneFS, versions 9.5.0.0 through 9.7.1.15, versions 9.8.0.0 through 9.13.1.0, and versions prior to 9.15.0.0, contain an Incorrect Authorization vulnerability. A low privileged adjacent network attacker could potentially exploit this vulnerability, leading to unauthorized modification of system logs.\n\n## Affected\n\n- `powerscale_onefs >= 9.5.0.0, <= 9.7.1.15`\n- `powerscale_onefs >= 9.8.0.0, <= 9.13.1.0`\n- `powerscale_onefs >= 9.14.0.0, < 9.15.0.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `powerscale_onefs 9.15.0.0`","depth":"sunlit","depthScore":19,"depthScoreParts":{"impact":19.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}