CVE-2026-28265 details a Path Traversal vulnerability within Dell PowerStore products, specifically impacting the Service user. With a CVSSv3.1 score of 7.1 High, this flaw enables a low-privileged local attacker to modify arbitrary system files, posing a high risk to system integrity and availability. Currently, there is no public exploit code available, and it is not included in CISA's Known Exploited Vulnerabilities catalog. Despite its presence on a "Hot List," community discussion and media coverage are absent, and its EPSS score suggests a very low probability of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.4.0.0-2692403CPE matchmatch criteria | cpe:2.3:o:dell:powerstoreos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.