Dell PowerFlex Manager Improper Access Control Allows Priv Esc
CVE-2026-35067 Published on June 17, 2026
Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper Access Control vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Elevation of privileges and Unauthorized access.
Vulnerability Analysis
Attack Vector:
ADJACENT_NETWORK
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
NONE
Availability Impact:
NONE
Weakness Type
What is an Authorization Vulnerability?
The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVE-2026-35067 has been classified to as an Authorization vulnerability or weakness.
Affected Versions
Dell PowerFlex:- Before 5.1.0.1 or later is affected.
- Before 4.5.5.2 or later is affected.