CVE-2026-40636Disclosure(dell / elastic_cloud_storage)

MEDIUMCVSS 7.8 · HIGH

Exploitation ongoing with high activity in latest observed window (4 mentions)

Immediate actions

  • Patch dell elastic_cloud_storage systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains a use of hard-coded credentials vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to filesystem access for attacker.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-798

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • elastic_cloud_storage
  • objectscale

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 12 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 8 signals
  • Disclosure: 8 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 5 mentions (2026-05-11); latest day: 4
  • 12 total mentions across 5 days

Affected systems

Vendors
Products
elastic_cloud_storageobjectscale

Deep dive

Activity timeline12 mentions / 5d
01345Mentions · 2026-05-11: 5Mentions · 2026-05-12: 1Mentions · 2026-05-13: 1Mentions · 2026-05-19: 1Mentions · 2026-06-06: 4Active Exploitation · 2026-05-11: 1Patch / Workaround · 2026-05-12: 1Technical Details · 2026-05-11: 2Technical Details · 2026-05-12: 1Technical Details · 2026-05-19: 1Technical Details · 2026-06-06: 405-1105-1205-1305-1906-06
Signal classification4 categories
Disclosure
866.7%
General
216.7%
Active Exploitation
18.3%
Patch
18.3%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-05-115
Active Exploitation1Disclosure3General1
2026-05-121
Patch1
2026-05-131
General1
2026-05-191
Disclosure1
2026-06-064
Disclosure4
Full discourse12 posts
  • Wazuh@wazuh
    Disclosure

    Dell ECS and ObjectScale are affected by CVE-2026-40636 (CVSS 9.8), a critical hard-coded credentials flaw that may allow unauthenticated local attackers to gain access to the filesystem. Affects ECS 3.8.1.0–3.8.1.7 and ObjectScale < 4.3.0.0. Read more: https://ow.ly/9vsP50Z1AJy https://t.co/sxZUc7H8zB

    Post summary

    Dell ECS and ObjectScale are affected by the critical CVE‑2026‑40636 hard‑coded credentials flaw, allowing local attackers to access the filesystem, with no evidence of active exploitation or available PoC.

    060102533
    8.1K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Urgent: Dell patches a 9.8 severity credential flaw (CVE-2026-40636) in ECS and ObjectScale. Secure your enterprise storage by upgrading to version 4.3.0.0. #DellSecurity #EnterpriseStorage #CyberSecurity #InfoSec #PatchNow #DataProtection #Vulnerability https://securityonline.info/dell-ecs-objectscale-security-update-cve-2026-40636/ https://t.co/pjkGrLVcao

    Post summary

    Dell has released a patch for CVE-2026-40636, a 9.8‑severity credential flaw in ECS and ObjectScale, and advises upgrading to version 4.3.0.0.

    12093608
    12.5K followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Attention, elevated activities detected targeting Dell ECS and ObjectScale (CVE-2026-40636) https://vuldb.com/vuln/362603/cti

    Post summary

    Alert notes that attackers are actively targeting Dell ECS/ObjScale for CVE-2026-40636, with no disclosed PoC, patch, or exploit tool.

    0201081
    2.2K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A severe vulnerability was disclosed for Dell ECS and ObjectScale (CVE-2026-40636) https://vuldb.com/vuln/362603

    Post summary

    The post announces the disclosure of CVE‑2026‑40636 as a severe vulnerability affecting Dell ECS and ObjectScale, pointing to a vulnerability database entry.

    0102082
    2.3K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Full Tweet Dell ECS and ObjectScale are affected by CVE-2026-40636 (CVSS 9.8), a critical hard-coded credentials flaw that may allow unauthenticated local attackers to gain access to the filesystem. Affects ECS 3.8.1.0–3.8.1.7 and ObjectScale < 4.3.0.0.

    Post summary

    Dell ECS and ObjectScale are impacted by CVE-2026-40636, a critical hard‑coded credentials flaw (CVSS 9.8) that could allow unauthenticated local attackers to access the filesystem; the tweet lists affected ECS and ObjectScale versions.

    1000020
    247 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Source: X search for CVE-2026 critical Posted: 2026-05-19T12:57:02.000Z Likes: 10 0day Intel: Dell ECS and ObjectScale are affected by CVE-2026-40636 (CVSS 9.8), a critical h

    Post summary

    The post announces a new critical vulnerability (CVE‑2026‑40636) affecting Dell ECS and ObjectScale, noting a CVSS score of 9.8, but provides no exploit code, mitigation steps, or evidence of active exploitation.

    1000022
    247 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-40636: Dell ECS and ObjectScale are affected by CVE-2026-40636 (CVSS 9.8), a critical hard-coded credentials flaw that may allow unauthenticated local attackers to gain access to the filesystem. Affects ECS 3.8.1.0–3.8.1.7 and ObjectScale < 4.3.0.0. Read more:…

    Post summary

    Dell ECS and ObjectScale versions are vulnerable to CVE-2026-40636, a critical hard‑coded credentials flaw that permits unauthenticated local attackers to access the filesystem.

    1000025
    247 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    0day Intel: Dell ECS and ObjectScale are affected by CVE-2026-40636 (CVSS 9.8), a critical h

    Post summary

    The post announces that Dell ECS and ObjectScale are affected by the critical CVE-2026-40636 (CVSS 9.8), but provides no further technical, exploit, or mitigation details.

    1000021
    247 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    General

    Dell ECSとObjectScaleに重大な脆弱性(CVE-2026-40636 他) https://rocket-boys.co.jp/security-measures-lab/dell-ecs-objectscale-critical-flaws-cve-2026-40636/ #セキュリティ対策Lab #security #securitynews

    Post summary

    The post alerts that Dell ECS and ObjectScale contain a serious vulnerability (CVE-2026-40636) and provides a link, but offers no additional technical or mitigation details.

    0000079
    405 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40636 Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains a use of hard-coded credentials vulnerability. An unauthenticated a… https://www.cve.org/CVERecord?id=CVE-2026-40636

    Post summary

    Dell ECS and ObjectScale contain a hard‑coded credentials vulnerability (CVE‑2026‑40636) that allows unauthenticated access on specific version ranges.

    00000104
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-40636 Hard-Coded Credentials Vulnerability in Dell ECS and ObjectScale Versions https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40636

    Post summary

    The content announces a hard‑coded credentials vulnerability (CVE‑2026‑40636) in Dell ECS and ObjectScale, but provides no technical specifics, PoC, exploit details, patch information, or evidence of active exploitation.

    0000051
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🚨 CRITICAL — CVE-2026-40636 Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains a use of hard-coded … CVSS 9.8 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-40636 #Dell #CyberSecurity #InfoSec

    Post summary

    Dell ECS and ObjectScale products are susceptible to CVE-2026-40636 with a CVSS score of 9.8; no patch is available, but technical details and an external analysis link are provided.

    0000061
    90 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appdellelastic_cloud_storage---
Appdellobjectscale---

Explore more