Medium severity6.4NVD Advisory· Published May 20, 2026· Updated Jul 24, 2026
CVE-2026-35070
CVE-2026-35070
Description
Dell SmartFabric Storage Software, versions prior to 1.4.5, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:dell:smartfabric_storage_software:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:dell:smartfabric_storage_software:*:*:*:*:*:*:*:*range: <1.4.5
- (no CPE)range: <1.4.5
Patches
Vulnerability mechanics
References
1News mentions
1- Dell Discloses 13 CVEs Across PowerFlex, ECS, VxRail, and MoreVypr Intelligence · May 22, 2026