Critical Dell ObjectScale Vulnerabilities Allows Malicious Users to Compromise the Affected system
Brief
Dell Technologies released a security advisory about multiple vulnerabilities affecting Dell ObjectScale and Elastic Cloud Storage (ECS) deployments.
Including a critical remote code execution flaw that could let an unauthenticated attacker compromise vulnerable systems. The advisory, tracked as DSA-2026-393, was published on September 10, 2026.
The most severe issue is CVE-2026-70416, a critical untrusted-data deserialization vulnerability in Dell ObjectScale versions earlier than 4.
- 0.
- The flaw carries a CVSS score of 10.
- It could allow an unauthenticated remote attacker to execute code on an affected system.
Successful exploitation could give an attacker control over the ObjectScale environment, enabling them to access data, alter configurations, disrupt storage operations, deploy malicious payloads, or establish persistence in the affected infrastructure.
