Critical Dell ObjectScale Vulnerabilities Enable Unauthenticated RCE
Dell has disclosed multiple vulnerabilities in its ObjectScale and Elastic Cloud Storage (ECS) products, including a critical flaw allowing unauthenticated remote code execution.

Dell Technologies has issued a security advisory, DSA-2026-393, detailing a series of vulnerabilities affecting its Dell ObjectScale and Elastic Cloud Storage (ECS) platforms. The most severe of these is CVE-2026-70416, a critical untrusted-data deserialization vulnerability with a CVSS score of 10.0. This flaw, present in Dell ObjectScale versions prior to 4.4.0.0, could allow an unauthenticated remote attacker to execute arbitrary code on a vulnerable system.
Successful exploitation of CVE-2026-70416 could grant an attacker significant control over the affected ObjectScale environment. This could lead to unauthorized access to sensitive data, modification of system configurations, disruption of storage operations, deployment of malicious payloads, or the establishment of persistent access within the compromised infrastructure. Given that ObjectScale is designed for enterprise-scale object storage, a compromise could have far-reaching implications for organizations relying on it for backups, application data, archives, and cloud-native workloads.
In addition to the critical RCE vulnerability, Dell's advisory also highlights CVE-2025-43936, an improper authentication vulnerability rated with a CVSS score of 8.1. Affecting ObjectScale versions before 4.4.0.0, this flaw could permit an unauthenticated attacker with remote access to gain unauthorized entry into the system. While the attack complexity is noted as high, the absence of credential or user interaction requirements makes it a significant concern, underscoring the need to restrict network exposure.
Further vulnerabilities detailed in the advisory include CVE-2026-26947, an improper privilege management flaw (CVSS 6.7) affecting both Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions earlier than 4.4.0.0. This could allow a local attacker with high privileges to escalate their access, impacting data confidentiality, integrity, and availability. Another issue, CVE-2025-36591, a broken or risky cryptographic algorithm vulnerability (CVSS 4.4), could potentially expose sensitive information to a high-privileged local attacker.
The advisory also lists CVE-2026-76104, an incorrect permission assignment vulnerability in the operating system with a CVSS score of 5.5. This could enable a high-privileged remote attacker to induce denial-of-service conditions. Furthermore, Dell has acknowledged third-party component vulnerabilities within Apache Log4j, liblzma, and the Linux kernel, identified by CVEs such as CVE-2026-34477, CVE-2026-34478, CVE-2026-34480, CVE-2026-34743, CVE-2026-31694, and CVE-2026-43499.
Dell strongly recommends that customers upgrade their affected Dell ObjectScale and ECS systems to version 4.4.0.0 or later as a priority. For those running supported affected releases, an upgrade to version 4.2.0.1 is also an option. Organizations should initiate an Operating Environment Upgrade service request and reference DSA-2026-393. Until patches can be applied, Dell suggests implementing the Secure Service-Level Communication guidance from the official Security Configuration Guide to mitigate CVE-2025-43936.
In addition to patching, security teams are advised to restrict administrative and storage-management interfaces to trusted networks, meticulously review all exposed ObjectScale services, maintain vigilant monitoring for anomalous authentication activities, and promptly investigate any unexpected changes to configurations or permissions. Security researcher WinD39, also known as Huynh Dinh Vu, has been credited by Dell for reporting the critical CVE-2026-70416.