CVE-2026-22275
Inclusion of Sensitive Data in Dell ECS and ObjectScale
Publication date: 2026-01-23
Last updated on: 2026-02-18
Assigner: Dell
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| dell | elastic_cloud_storage | From 3.8.1.0 (inc) to 4.2.0.0 (exc) |
| dell | objectscale | to 4.2.0.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-540 | Source code on a web server or repository often contains sensitive information and should generally not be accessible to users. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an Inclusion of Sensitive Information in Source Code found in Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.2.0.0. It allows a low privileged attacker with local access to potentially exploit the vulnerability, leading to exposure of sensitive information.
How can this vulnerability impact me? :
The vulnerability can lead to information exposure by allowing a low privileged local attacker to access sensitive information included in the source code, which could compromise confidentiality and potentially aid further attacks.