CVE-2026-26359Disclosure(dell / unisphere_for_powermax)

LOWCVSS 8.8 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to the ability to overwrite arbitrary files.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-73

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • unisphere_for_powermax

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
unisphere_for_powermax

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-02-19: 4Technical Details · 2026-02-19: 302-19
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • The Hacker Wire@TheHackerWire
    General

    🟠 CVE-2026-26359 - High Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low privileged attacker with remote access could potentially exploit this vu... https://www.thehackerwire.com/vulnerability/CVE-2026-26359/ https://t.co/X2VLOht5O3

    Post summary

    The tweet announces CVE-2026-26359, describing it as an External Control of File Name or Path vulnerability with potential remote exploitation, but provides no proof of concept, exploit code, patch, or active exploitation evidence.

    0000036
    112 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-26359** pertains to a security flaw in **Dell Unisphere for PowerMax (version 10.2)**, classified as an **External Control of File Name or Path** vulnerability. This flaw allows an attacker with **low privileges and remote access** to manipulate file operations, specifically to **overwrite arbitrary files** on the affected system. #Cybersecurity #CVE #HighSeverity #SecurityAlert https://cvetodo.com/cve/CVE-2026-26359

    Post summary

    The text announces a new Dell Unisphere for PowerMax vulnerability (CVE-2026-26359) that allows file overwrite with low privileges, lacking evidence of exploitation or PoC.

    0000027
    20 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A new vulnerability with increased severity was disclosed for Dell Unisphere for PowerMax and PowerMax (CVE-2026-26359) https://vuldb.com/?id.346762

    Post summary

    A new vulnerability (CVE-2026-26359) affecting Dell Unisphere for PowerMax was disclosed with higher severity, but no further technical or mitigation details were provided.

    0000055
    2.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26359 Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low privileged attacker with remote access could po… https://www.cve.org/CVERecord?id=CVE-2026-26359

    Post summary

    Dell Unisphere for PowerMax 10.2 is affected by CVE‑2026‑26359, an External Control of File Name or Path vulnerability that could be exploited by low‑privileged remote attackers.

    0000061
    56.4K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appdellunisphere_for_powermax---
Appdellunisphere_for_powermax---

Explore more