---
id: CVE-2026-58574
title: >-
  Dell PowerStore contains a Missing Authentication for Critical Function
  vulnerability
summary: >-
  Dell PowerStore contains a Missing Authentication for Critical Function
  vulnerability. An unauthenticated attacker with network access to the
  restricted management interface could potentially exploit this vulnerability
  to read internal s…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-306
vendor: dell
product: powerstoreos
affected:
  - powerstoreos = 4.1.0.0
  - powerstoreos = 4.1.0.1
  - powerstoreos = 4.1.0.2
  - powerstoreos = 4.1.0.3
  - powerstoreos = 4.1.0.4
  - powerstoreos = 4.1.0.5
  - powerstoreos = 4.3.0.0
  - powerstoreos = 4.3.1.0
  - powerstoreos = 4.3.1.1
published: '2026-08-31'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T13:34:28.347'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-58574'
references:
  - url: >-
      https://www.dell.com/support/kbdoc/en-us/000497829/dsa-2026-330-dell-powerstore-t-security-update-for-multiple-vulnerabilities
    label: security_alert@emc.com
tags:
  - nvd
epss: 0.00625
epssPercentile: 0.47916
ingestedAt: '2026-10-01T13:44:55.810Z'
---

## Overview

Dell PowerStore contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with network access to the restricted management interface could potentially exploit this vulnerability to read internal system information from the appliance filesystem. This is a Critical vulnerability as it could expose sensitive information and credentials which allow full administrative access to the array.

## Affected

- `powerstoreos = 4.1.0.0`
- `powerstoreos = 4.1.0.1`
- `powerstoreos = 4.1.0.2`
- `powerstoreos = 4.1.0.3`
- `powerstoreos = 4.1.0.4`
- `powerstoreos = 4.1.0.5`
- `powerstoreos = 4.3.0.0`
- `powerstoreos = 4.3.1.0`
- `powerstoreos = 4.3.1.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
