Dell PowerStore SDNAS SMB/OOB Write Exploit Enables RCE
CVE-2026-67271 Published on August 18, 2026
Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the SMB/CIFS. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service and Remote execution. This is a Critical vulnerability as a remote user could send a specially crafted SMB packet and cause a crash, that is persistent in case automatic restarts are enabled. Additionally, a more sophisticated attacker could use the same vulnerability for Remote Code execution.
Vulnerability Analysis
CVE-2026-67271 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.
Weakness Type
What is a Memory Corruption Vulnerability?
The software writes data past the end, or before the beginning, of the intended buffer. Typically, this can result in corruption of data, a crash, or code execution. The software may modify an index or perform pointer arithmetic that references a memory location that is outside of the boundaries of the buffer. A subsequent write operation then produces undefined or unexpected results.
CVE-2026-67271 has been classified to as a Memory Corruption vulnerability or weakness.
Affected Versions
Dell PowerStore 500T:- Before 5.0.0.2-2761110 or later is affected.
- Before 5.0.0.2-2761110 or later is affected.
- Before 5.0.0.2-2761110 or later is affected.
- Before 5.0.0.2-2761110 or later is affected.
- Before 5.0.0.2-2761110 or later is affected.
- Before 5.0.0.2-2761110 or later is affected.
- Before 5.0.0.2-2761110 or later is affected.
- Before 5.0.0.2-2761110 or later is affected.
- Before 5.0.0.2-2761110 or later is affected.
- Before 5.0.0.2-2761110 or later is affected.
- Before 5.0.0.2-2761110 or later is affected.
- Before 5.0.0.2-2761110 or later is affected.