Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.1, contains an incorrect privilege assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.
History

Mon, 13 Apr 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Apr 2026 14:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Incorrect Privilege Assignment in Dell PowerScale OneFS

Mon, 13 Apr 2026 11:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:dell:powerscale_onefs:*:*:*:*:*:*:*:*

Thu, 09 Apr 2026 05:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Incorrect Privilege Assignment in Dell PowerScale OneFS

Wed, 08 Apr 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerscale Onefs
Vendors & Products Dell
Dell powerscale Onefs

Wed, 08 Apr 2026 12:45:00 +0000

Type Values Removed Values Added
Description Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.1, contains an incorrect privilege assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published: 2026-04-08T12:11:23.717Z

Updated: 2026-04-13T15:37:35.174Z

Reserved: 2026-02-17T18:05:21.467Z

Link: CVE-2026-27102

cve-icon Vulnrichment

Updated: 2026-04-08T17:41:24.316Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-08T13:16:41.370

Modified: 2026-04-13T11:38:11.023

Link: CVE-2026-27102

cve-icon Redhat

No data.