CVE-2026-40711
Awaiting Analysis
Awaiting Analysis - Queue
OS Command Injection in Dell Container Storage Modules
Publication date: 2026-06-26
Last updated on: 2026-06-26
Assigner: Dell
Description
Description
Dell Dell Container Storage Modules, version(s) csi-powerstore v2.16.0, csi-unity v2.16.0, csi-powerflex v2.16.0, csi-powermax v2.16.0, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| dell | csi_powerstore | 2.16.0 |
| dell | csi_unity | 2.16.0 |
| dell | csi_powerflex | 2.16.0 |
| dell | csi_powermax | 2.16.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-78 | The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component. |