---
id: CVE-2026-28265
title: 'PowerStore, contains a Path Traversal vulnerability in the Service user'
summary: >-
  PowerStore, contains a Path Traversal vulnerability in the Service user. A low
  privileged attacker with local access could potentially exploit this
  vulnerability, leading to modification of arbitrary system files.
severity: medium
cvss: 4.4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'
cwe:
  - CWE-35
  - CWE-22
vendor: dell
product: powerstoreos
affected:
  - 'powerstoreos >= 4.3.0.0, < 4.3.1.1'
patched:
  - powerstoreos 4.3.1.1
published: '2026-04-01'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T13:30:54.337'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-28265'
references:
  - url: >-
      https://www.dell.com/support/kbdoc/en-us/000444169/dsa-2026-157-dell-powerstore-t-security-update-for-multiple-vulnerabilities
    label: security_alert@emc.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-04-01T13:10:06.196625Z'
ingestedAt: '2026-09-13T04:36:46.868Z'
epss: 0.00117
epssPercentile: 0.01867
---

## Overview

PowerStore, contains a Path Traversal vulnerability in the Service user. A low privileged attacker with local access could potentially exploit this vulnerability, leading to modification of arbitrary system files.

## Affected

- `powerstoreos >= 4.3.0.0, < 4.3.1.1`

## Remediation

Upgrade past the affected range:

- `powerstoreos 4.3.1.1`
