CVE-2026-22275
Unknown Unknown - Not Provided
Inclusion of Sensitive Data in Dell ECS and ObjectScale

Publication date: 2026-01-23

Last updated on: 2026-02-18

Assigner: Dell

Description
Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains an Inclusion of Sensitive Information in Source Code vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-01-23
Last Modified
2026-02-18
Generated
2026-05-07
AI Q&A
2026-01-23
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
dell elastic_cloud_storage From 3.8.1.0 (inc) to 4.2.0.0 (exc)
dell objectscale to 4.2.0.0 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-540 Source code on a web server or repository often contains sensitive information and should generally not be accessible to users.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is an Inclusion of Sensitive Information in Source Code found in Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.2.0.0. It allows a low privileged attacker with local access to potentially exploit the vulnerability, leading to exposure of sensitive information.


How can this vulnerability impact me? :

The vulnerability can lead to information exposure by allowing a low privileged local attacker to access sensitive information included in the source code, which could compromise confidentiality and potentially aid further attacks.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart