Dell VSI vSphere Client <=10.11.1.0 SI Disclosure
CVE-2026-54489 Published on August 6, 2026
Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session hijacking. This vulnerability is considered critical as it allows an unauthenticated attacker to obtain active session credentials and fully impersonate authenticated users, including administrators. Dell recommends customers to upgrade at the earliest opportunity.
Vulnerability Analysis
CVE-2026-54489 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.
Weakness Type
What is an Information Disclosure Vulnerability?
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVE-2026-54489 has been classified to as an Information Disclosure vulnerability or weakness.
Affected Versions
Dell Virtual Storage Integrator for VMware vSphere Client:- Before 10.11.1.0 or later is affected.