CVE-2026-58574Critical· 9.8▾ MidnightDell PowerStore contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with network access to the restricted management interface could potentially exploit this vulnerability to read internal s…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.6%
Dell PowerStore contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with network access to the restricted management interface could potentially exploit this vulnerability to read internal system information from the appliance filesystem. This is a Critical vulnerability as it could expose sensitive information and credentials which allow full administrative access to the array.
powerstoreos = 4.1.0.0powerstoreos = 4.1.0.1powerstoreos = 4.1.0.2powerstoreos = 4.1.0.3powerstoreos = 4.1.0.4powerstoreos = 4.1.0.5powerstoreos = 4.3.0.0powerstoreos = 4.3.1.0powerstoreos = 4.3.1.1Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-58575High· 8.8Dell PowerStore contains an Authentication Bypass by Spoofing vulnerability
CVE-2026-79683High· 8.8Dell PowerStore contains a Protection Mechanism Failure vulnerability
CVE-2026-76111High· 8.8Dell PowerStore contains an Incorrect Authorization vulnerability
CVE-2026-81455High· 8.6Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contain a Missing Authentication for Critical Function vulnerability
CVE-2026-73588High· 7.4Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing Authentication for Critical Function vulnerability
CVE-2026-81475High· 8.1Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability