DSA-2026-393: Security update for Dell ObjectScale Multiple Vulnerabilities
摘要: Dell ObjectScale remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
本文章適用於
本文章不適用於
本文無關於任何特定產品。
本文未識別所有產品版本。
影響
Critical
詳細資料
| Third-party Component | CVEs | More Information |
| Apache Log4j | CVE-2026-34477, CVE-2026-34478, CVE-2026-34480 | https://nvd.nist.gov/vuln/search |
| liblzma | CVE-2026-34743 | https://nvd.nist.gov/vuln/search |
| Linux Kernel | CVE-2026-31694, CVE-2026-43499 | https://nvd.nist.gov/vuln/search |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2026-70416 | Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. | 10.0 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| CVE-2025-43936 | Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | 8.1 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-26947 | Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Improper Privilege Management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | 6.7 | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-76104 | Dell ObjectScale, versions prior to 4.4.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability in the OS. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service. | 5.5 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2026-70416 | Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. | 10.0 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| CVE-2025-43936 | Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | 8.1 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-26947 | Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Improper Privilege Management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | 6.7 | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-76104 | Dell ObjectScale, versions prior to 4.4.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability in the OS. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service. | 5.5 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H |
受影響的產品與補救措施
| Product | Affected Versions | Remediated Versions | Link |
| Elastic Cloud Storage (ECS) | Versions 3.x through 3.8.1.7 | Version 4.4.0.0 or later | Open a Service Request for an Operating Environment Upgrade and Quote DSA-2026-393 |
| ObjectScale | Versions prior to 4.4.0.0 | Open a Service Request for an Operating Environment Upgrade and Quote DSA-2026-393 |
| Product | Affected Versions | Remediated Versions | Link |
| Elastic Cloud Storage (ECS) | Versions 3.x through 3.8.1.7 | Version 4.4.0.0 or later | Open a Service Request for an Operating Environment Upgrade and Quote DSA-2026-393 |
| ObjectScale | Versions prior to 4.4.0.0 | Open a Service Request for an Operating Environment Upgrade and Quote DSA-2026-393 |
Note:
- Customers on any supported affected versions/releases listed in the ‘Affected Products and Remediation’ section may also upgrade directly to the 4.4.0.0 release.
- Dell recommends all customers have their ObjectScale systems upgraded at the earliest opportunity by opening an “Operating Environment Upgrade” Service Request.
- Please visit the Security Update Release Schedule for Supported Versions of ObjectScale (formerly ECS) for more information.
因應措施與緩解措施
| CVE ID | Workaround and Mitigation |
| CVE-2025-43936 | Secure Service-Level Communication section in the official "Security Configuration Guide" |
修訂歷史記錄
| Revision | Date | Description |
| 1.0 | 2026-09-10 | Initial Release |
| 2.0 | 2026-09-11 | Minor updates |
| 3.0 | 2026-09-14 | Minor changes - correction on text |
| 4.0 | 2026-09-17 | Removed CVE-2025-36591 |
感謝
CVE-2026-70416: Dell would like to thank WinD39 - Huynh Dinh Vu for reporting this issue.
相關資訊
法律免責聲明
受影響的產品
ECS, ObjectScale, ECS Appliance, ECS Appliance Hardware Series, ECS Appliance Software with Encryption, ECS Appliance Software without Encryption, ObjectScale Software with Encryption, ObjectScale Software without Encryption
, ObjectScale Appliance Series, ObjectScale Software Series
...
文章屬性
文章編號: 000505935
文章類型: Dell Security Advisory
上次修改時間: 18 9月 2026
向其他 Dell 使用者尋求您問題的答案
支援服務
檢查您的裝置是否在支援服務的涵蓋範圍內。