CVE-2026-22273
Use of Default Credentials in Dell ECS/ObjectScale Enables Privilege Escalation
Publication date: 2026-01-23
Last updated on: 2026-02-18
Assigner: Dell
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| dell | elastic_cloud_storage | From 3.8.1.0 (inc) to 4.2.0.0 (exc) |
| dell | objectscale | to 4.2.0.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1392 | The product uses default credentials (such as passwords or cryptographic keys) for potentially critical functionality. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a Use of Default Credentials issue in Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.2.0.0. It allows a low privileged attacker with remote access to exploit the system by using default credentials, potentially leading to an elevation of privileges.
How can this vulnerability impact me? :
An attacker exploiting this vulnerability could gain elevated privileges on the affected system, which may allow them to access, modify, or delete sensitive data, disrupt services, or perform unauthorized actions, leading to significant security risks.