
Dellは、VMware vSphere Client向けVirtual Storage Integrator(VSI)の脆弱性2件を修正した。CVE-2026-67261は認証なしでroot権限の任意コマンド実行が可能で、CVE-2026-54489はセッション窃取につながる。 CVE-2026-67261はIAPIコンポーネントのOSコマンドインジェクションで、10.11.1.0未満のVSIが影響を受ける。Dellによると、リモートの未認証攻撃者がroot権限で任意のOSコマンドを実行でき、システム全体の乗っ取りにつながる可能性がある。 CVE-2026-54489は機密情報の漏えいで、未認証の攻撃者が有効なセッション資格情報を取得し、管理者を含む認証済みユーザーになりすませる。 両脆弱性はVSI 10.11.1.0以降で修正された。Dellは可能な限り早いアップグレードを推奨しており、回避策は提供されていない。記事によると、現時点で実際の悪用は確認されていない。 https://securityonline.info/dell-vsi-cve-2026-67261-unauthenticated-rce/
Post summary
Dell has issued patches for two VMware vSphere Client VSI vulnerabilities (CVE-2026-67261 and CVE-2026-54489), detailing the technical impact and urging early upgrades, with no evidence of current exploitation.





