Dell Technologies released a security advisory about multiple vulnerabilities affecting Dell ObjectScale and Elastic Cloud Storage (ECS) deployments.
Including a critical remote code execution flaw that could let an unauthenticated attacker compromise vulnerable systems. The advisory, tracked as DSA-2026-393, was published on September 10, 2026.
The most severe issue is CVE-2026-70416, a critical untrusted-data deserialization vulnerability in Dell ObjectScale versions earlier than 4.4.0.0. The flaw carries a CVSS score of 10.0. It could allow an unauthenticated remote attacker to execute code on an affected system.
Successful exploitation could give an attacker control over the ObjectScale environment, enabling them to access data, alter configurations, disrupt storage operations, deploy malicious payloads, or establish persistence in the affected infrastructure.
ObjectScale provides enterprise-scale object storage, so a compromise could be significant for organizations that store backups, application data, archives, or cloud-native workloads on the platform.
Dell ObjectScale Vulnerabilities
Dell’s advisory also details CVE-2025-43936, an improper authentication vulnerability rated 8.1. The flaw affects ObjectScale versions before 4.4.0.0 and may allow an unauthenticated attacker with remote access to gain unauthorized access.
Although its attack complexity is rated high, the vulnerability does not require credentials or user interaction, increasing the importance of limiting network exposure while updates are deployed.
Two additional flaws affect both Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions earlier than 4.4.0.0. CVE-2026-26947 is an improper privilege management flaw with a CVSS score of 6.7.
A local attacker with high privileges could exploit it to elevate privileges further and affect confidentiality, integrity, and availability.
CVE-2025-36591 is a broken or risky cryptographic algorithm vulnerability rated 4.4. Dell said a high-privileged local attacker could potentially exploit the issue to expose sensitive information.
Another issue, CVE-2026-76104, is an incorrect permission assignment vulnerability in the operating system. It has a CVSS score of 5.5 and could allow a high-privileged remote attacker to cause denial-of-service conditions.
The advisory also lists third-party component vulnerabilities involving Apache Log4j, liblzma, and the Linux kernel. These include CVE-2026-34477, CVE-2026-34478, CVE-2026-34480, CVE-2026-34743, CVE-2026-31694, and CVE-2026-43499.
Dell recommends that customers upgrade affected ObjectScale and ECS systems to version 4.4.0.0 or later as soon as possible. Customers running supported affected releases may also upgrade directly to version 4.2.0.1. Organizations should open an Operating Environment Upgrade service request and reference DSA-2026-393.
Until updates are applied, Dell recommends using the Secure Service-Level Communication guidance in the official Security Configuration Guide to mitigate CVE-2025-43936.
Security teams should also restrict administrative and storage-management interfaces to trusted networks, review exposed ObjectScale services, monitor for abnormal authentication activity, and investigate unexpected configuration or permission changes. Dell credited security researcher WinD39, also known as Huynh Dinh Vu, for reporting CVE-2026-70416.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

