VYPR
Medium severity5.4NVD Advisory· Published Feb 17, 2026· Updated Apr 15, 2026

CVE-2026-26357

CVE-2026-26357

Description

Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to the execution of malicious HTML or JavaScript code in a victim user's web browser in the context of the vulnerable web application. Exploitation may lead to information disclosure, session theft, or client-side request forgery.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CVE-2026-26357 is a stored cross-site scripting vulnerability in Dell Unisphere for PowerMax 9.2.4.x that lets a low-privileged attacker inject malicious scripts leading to session theft and data disclosure.

Vulnerability

Overview

CVE-2026-26357 is a stored cross-site scripting (XSS) vulnerability affecting Dell Unisphere for PowerMax, version 9.2.4.x. The root cause lies in improper neutralization of user-supplied input during web page generation. A low-privileged attacker with remote access can inject arbitrary HTML or JavaScript that, when rendered by an authenticated victim's browser, executes in the context of the vulnerable Unisphere application. [1]

Attack

Scenario

An attacker authenticated with low privileges can craft a malicious payload and submit it through an input field or other user-controllable parameter. No further privileges are required beyond the initial low-level access. When a privileged user (or any victim) browses to the affected page, the injected script executes in their browser session. This requires no specific interaction beyond normal use of the web interface. [1]

Impact

Successful exploitation allows the attacker to steal session cookies, exfiltrate sensitive data, or perform client-side request forgery (CSRF) on behalf of the victim. Since the attack executes within the victim's authenticated session, it can bypass normal access controls and lead to unauthorized actions and information disclosure. [1]

Mitigation

Dell has released a security advisory (DSA-2025-425) as part of a broader update that addresses this vulnerability along with numerous other CVEs. Users are strongly encouraged to update their Dell Unisphere for PowerMax installations to the latest patched version to mitigate this risk. [1]

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.