Dell PowerStore Management Interface Missing Authentication for Critical Function Vulnerability (CVE-2026-58574)

Release Date: 31st August 2026 (Added 9 September 2026)

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that operate Dell PowerStore storage arrays. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-58574 (CVSS 3.1 base score 9.8, Critical, CWE-306: Missing Authentication for Critical Function) affects the management interface of Dell PowerStore. An unauthenticated remote attacker with network access to the restricted management interface can exploit the vulnerability to read internal system information directly from the appliance filesystem, with no privileges or user interaction required, potentially exposing credentials that grant full administrative access to the array.

Reference

  1. https://www.dell.com/support/kbdoc/en-us/000497829/dsa-2026-330-dell-powerstore-t-security-update-for-multiple-vulnerabilities
  2. https://www.cve.org/CVERecord?id=CVE-2026-58574