Dell Technologies has issued a crucial security advisory concerning several vulnerabilities impacting its ObjectScale and Elastic Cloud Storage (ECS) systems. Among these issues is a severe remote code execution vulnerability that could allow unauthorized users to compromise affected systems. This advisory, labeled DSA-2026-393, was released on September 10, 2026.
Details of the Vulnerabilities
The most critical vulnerability, identified as CVE-2026-70416, involves a deserialization flaw in Dell ObjectScale versions before 4.4.0.0. This vulnerability has been assigned the highest CVSS score of 10.0, indicating its potential to allow remote attackers to execute arbitrary code on unpatched systems.
If exploited successfully, this flaw could provide attackers full control over the ObjectScale environment, granting them the ability to access sensitive data, modify configurations, disrupt operations, deploy harmful software, or maintain a persistent presence within the infrastructure.
Given that ObjectScale is used for enterprise-level object storage, any breach could have profound implications, especially for organizations that use it for storing backups, application data, or cloud-native workloads.
Additional Vulnerabilities and Impact
Another notable vulnerability, CVE-2025-43936, relates to improper authentication and carries a CVSS score of 8.1. This issue affects ObjectScale versions prior to 4.4.0.0 and could allow remote attackers unauthorized access without requiring credentials or user interaction.
Additional vulnerabilities include CVE-2026-26947, an improper privilege management flaw with a CVSS score of 6.7, and CVE-2025-36591, a cryptographic algorithm weakness rated at 4.4. Both vulnerabilities could be exploited by high-privileged local attackers to compromise system confidentiality, integrity, and availability.
CVE-2026-76104, another issue with a CVSS score of 5.5, involves incorrect permission assignments that could enable a denial-of-service attack by high-privileged remote users.
Mitigation and Recommendations
Dell advises affected users to update their ObjectScale and ECS systems to version 4.4.0.0 or later. Those running supported versions may also upgrade to 4.2.0.1. It is recommended to request an Operating Environment Upgrade service and reference the advisory DSA-2026-393.
In the interim, Dell recommends employing Secure Service-Level Communication as outlined in their Security Configuration Guide to mitigate CVE-2025-43936. Security teams are urged to restrict access to administrative interfaces, monitor for unusual activity, and review exposed services.
Dell acknowledged security researcher WinD39, also known as Huynh Dinh Vu, for identifying CVE-2026-70416. Organizations are encouraged to remain vigilant and take immediate action to secure their systems.
