Dell PowerScale OneFS 9.5-9.15 Incorrect Auth Lets Adjac. Attacker Modify Logs
CVE-2026-46460 Published on September 9, 2026

Dell PowerScale OneFS, versions 9.5.0.0 through 9.7.1.15, versions 9.8.0.0 through 9.13.1.0, and versions prior to 9.15.0.0, contain an Incorrect Authorization vulnerability. A low privileged adjacent network attacker could potentially exploit this vulnerability, leading to unauthorized modification of system logs.

Vendor Advisory NVD

Vulnerability Analysis

Attack Vector:
ADJACENT_NETWORK
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
NONE
Integrity Impact:
LOW
Availability Impact:
NONE

Weakness Type

What is an AuthZ Vulnerability?

The software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.

CVE-2026-46460 has been classified to as an AuthZ vulnerability or weakness.


Products Associated with CVE-2026-46460

Want to know whenever a new CVE is published for Dell Powerscale Onefs? stack.watch will email you.

 

Affected Versions

Dell PowerScale OneFS: