CVE-2026-67261Disclosure(dell / virtual_storage_integrator)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch dell virtual_storage_integrator systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying operating system with root privileges. Exploitation may lead to a complete system takeover by an attacker. This vulnerability is considered critical as it allows an unauthenticated remote attacker to achieve arbitrary code execution as root, potentially compromising the entire VSI deployment and underlying infrastructure. Dell recommends customers to upgrade at the earliest opportunity.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • virtual_storage_integrator

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-08-07); latest day: 2
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
virtual_storage_integrator

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-08-06: 1Mentions · 2026-08-07: 3Mentions · 2026-08-12: 2Patch / Workaround · 2026-08-07: 1Patch / Workaround · 2026-08-12: 2Technical Details · 2026-08-06: 1Technical Details · 2026-08-07: 1Technical Details · 2026-08-12: 208-0608-0708-12
Signal classification2 categories
Disclosure
350.0%
Patch
350.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-08-061
Disclosure1
2026-08-073
Disclosure2Patch1
2026-08-122
Patch2
Full discourse6 posts
  • yousukezan@yousukezan
    Patch

    Dellは、VMware vSphere Client向けVirtual Storage Integrator(VSI)の脆弱性2件を修正した。CVE-2026-67261は認証なしでroot権限の任意コマンド実行が可能で、CVE-2026-54489はセッション窃取につながる。 CVE-2026-67261はIAPIコンポーネントのOSコマンドインジェクションで、10.11.1.0未満のVSIが影響を受ける。Dellによると、リモートの未認証攻撃者がroot権限で任意のOSコマンドを実行でき、システム全体の乗っ取りにつながる可能性がある。 CVE-2026-54489は機密情報の漏えいで、未認証の攻撃者が有効なセッション資格情報を取得し、管理者を含む認証済みユーザーになりすませる。 両脆弱性はVSI 10.11.1.0以降で修正された。Dellは可能な限り早いアップグレードを推奨しており、回避策は提供されていない。記事によると、現時点で実際の悪用は確認されていない。 https://securityonline.info/dell-vsi-cve-2026-67261-unauthenticated-rce/

    Post summary

    Dell has issued patches for two VMware vSphere Client VSI vulnerabilities (CVE-2026-67261 and CVE-2026-54489), detailing the technical impact and urging early upgrades, with no evidence of current exploitation.

    010901.6K
    15.0K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    Dell VSI for VMware vSphere Client has a critical unauthenticated RCE flaw (CVE-2026-67261) rated CVSS 9.8. Patch now. #CVE202667261 #DellVSI #RCE #VMware #CVSS #InfoSec http://securityonline.info/dell-vsi-cve-2026-67261-unauthenticated-rce/

    Post summary

    A critical, unauthenticated RCE vulnerability (CVE‑2026‑67261) in Dell VSI for VMware vSphere Client has been disclosed with a CVSS score of 9.8, and an immediate patch is available.

    00002448
    12.7K followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical command injection vulnerability in Dell Virtual Storage Integrator for VMware vSphere Client. CVE-2026-67261 CVSS: 9.8. This can allow a remote unauthenticated attacker to perform command execution. #Patch #Patch #Patch

    Post summary

    Dell Virtual Storage Integrator for VMware vSphere Client has a critical command injection flaw (CVE-2026-67261) enabling remote command execution; no exploit or patch details are provided.

    01000313
    7.2K followersView on X
  • SecureShield@SecureShield_
    Patch

    一次情報(NVD): https://nvd.nist.gov/vuln/detail/CVE-2026-67261 参照元(ベンダー等): https://www.dell.com/support/kbdoc/en-us/000496035/dsa-2026-335-security-update-for-dell-virtual-storage-integrator-for-vmware-vsphere-client-multiple-vulnerabilities

    Post summary

    The post references CVE‑2026‑67261 and a Dell security update, indicating a patch is available, but offers no technical details or exploitation evidence.

    0000060
    25 followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidad en productos DELL ❗ CVE-2026-67261 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-vmware-4/ https://t.co/BlbHPy3fPZ

    Post summary

    The tweet announces CVE-2026-67261 impacting Dell products and directs readers to external links for more information.

    00000247
    6.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-67261 Remote OS Command Injection in Dell Virtual Storage Integrator for VMware vSphere https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-67261

    Post summary

    A new CVE (CVE-2026-67261) detailing a remote OS command injection in Dell Virtual Storage Integrator for VMware vSphere is reported, with no PoC, exploit, patch, or active exploitation mentioned.

    00000148
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdellvirtual_storage_integrator-vmware_vsphere-

Explore more