CVE-2026-67262
Published on August 18, 2026

Dell PowerStore contains a Missing Authorization vulnerability. An attacker with access to a mapped host could exploit this vulnerability to read from or write to LUNs that the host is not authorized to access, bypassing per-initiator LUN access controls and leading to protection mechanism bypass.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-67262 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.

Attack Vector:
NETWORK
Attack Complexity:
HIGH
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH

Weakness Type

What is an AuthZ Vulnerability?

The software does not perform an authorization check when an actor attempts to access a resource or perform an action.

CVE-2026-67262 has been classified to as an AuthZ vulnerability or weakness.


Affected Versions

Dell PowerStore 500T: Dell PowerStore 1000T: Dell PowerStore 1200T: Dell PowerStore 3000T: Dell PowerStore 3200Q: Dell PowerStore 3200T: Dell PowerStore 5000T: Dell PowerStore 5200Q: Dell PowerStore 5200T: Dell PowerStore 7000T: Dell PowerStore 9000T: Dell PowerStore 9200T: