Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability during OS Repository processing to achieve arbitrary command execution as root, potentially leading to full appliance compromise and lateral movement into managed infrastructure.

Project Subscriptions

Vendors Products
Powerflex Manager Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 25 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Root-Privilege OS Command Injection in Dell PowerFlex Manager

Tue, 21 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Dell PowerFlex Manager Allows Root Compromise

Fri, 17 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Dell PowerFlex Manager Allows Root Compromise

Tue, 14 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Improper Neutralization of OS Command Leading to Root Execution in Dell PowerFlex Manager

Mon, 13 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Improper Neutralization of OS Command Leading to Root Execution in Dell PowerFlex Manager

Sun, 12 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Dell PowerFlex Manager Allows Arbitrary Root Execution

Sat, 11 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Dell PowerFlex Manager Allows Arbitrary Root Execution

Fri, 10 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerflex Manager
Vendors & Products Dell
Dell powerflex Manager

Fri, 10 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Description Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability during OS Repository processing to achieve arbitrary command execution as root, potentially leading to full appliance compromise and lateral movement into managed infrastructure.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-07-10T17:01:12.022Z

Reserved: 2026-06-22T17:04:26.238Z

Link: CVE-2026-56688

cve-icon Vulnrichment

Updated: 2026-07-10T16:49:54.255Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-25T20:15:02Z

Weaknesses