HIGH 7.1

CVE-2026-35066: Dell PowerFlex Manager Improper Access Control – DoS Vulnerability

Dell PowerFlex Manager versions before 5.1.0.1 contain an access control flaw that allows low-privileged remote attackers to cause denial of service. The vulnerability stems from improper enforcement of access restrictions, enabling an authenticated attacker to disrupt availability of the management platform without requiring elevated permissions or user interaction.

Source data · NVD / CISA · public domain

CVSS
3.1 · 7.1 HIGH · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Weaknesses (CWE)
CWE-284
Affected products
1 configuration(s)
Published / Modified
2026-06-17 / 2026-06-25

NVD description (verbatim)

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to denial of service.

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-35066 is an improper access control vulnerability (CWE-284) in Dell PowerFlex Manager affecting versions prior to 5.1.0.1. The flaw allows a low-privileged, remotely-authenticated user to trigger a denial-of-service condition. The CVSS 3.1 score of 7.1 (HIGH severity) reflects the network-accessible attack vector, low complexity, low privilege requirement, and high availability impact, though confidentiality and integrity are not directly affected. The vulnerability requires an existing user account but no special user interaction to exploit.

Business impact

Exploitation could cause temporary or extended unavailability of PowerFlex Manager, disrupting storage infrastructure administration, monitoring, and provisioning operations. Organizations dependent on PowerFlex for storage management may experience operational delays, potential SLA violations, and reduced visibility into their storage environment. The attack requires authentication but not admin privileges, widening the attack surface to any user account in the system.

Affected systems

Dell PowerFlex Manager versions prior to 5.1.0.1 are vulnerable. Organizations running affected versions should audit their current deployments and prioritize upgrades. The vulnerability affects the management interface itself, meaning any organization using PowerFlex Manager for infrastructure management may be impacted if running unpatched versions.

Exploitability

Exploitability is moderate to high in realistic environments. The attack requires network access and a valid user account with low privileges—credentials that may already be compromised, widely distributed, or belong to contractors and service accounts with limited intended access. No special tools or sophisticated techniques are needed; the low attack complexity suggests the vulnerability is straightforward to trigger once authentication is obtained. However, the current threat landscape assessment shows this vulnerability is not yet listed on the CISA Known Exploited Vulnerabilities catalog.

Remediation

Upgrade Dell PowerFlex Manager to version 5.1.0.1 or later. Organizations should verify the exact current version in their environment, test the patch in a non-production setting, and plan a controlled rollout to minimize operational disruption. Dell's official advisory should be consulted for any version-specific migration guidance or prerequisites.

Patch guidance

1. Identify all systems running Dell PowerFlex Manager and determine their current versions. 2. Consult Dell's official security advisory and release notes for version 5.1.0.1 and later to confirm patch availability and any compatibility considerations. 3. Test the upgrade in a development or staging environment matching your production configuration. 4. Schedule the upgrade during a maintenance window; verify rollback procedures beforehand. 5. After patching, confirm successful deployment and re-enable any security monitoring or access controls that may have been temporarily disabled. 6. Document the patched version and patch date for compliance tracking.

Detection guidance

Monitor PowerFlex Manager logs for abnormal access patterns from low-privileged accounts, repeated failed operations, or service restarts that might indicate exploitation attempts. Watch for unusual API calls or CLI commands originating from authenticated sessions that do not correspond to legitimate administrative activities. Network-level monitoring should track unexpected traffic spikes or connection patterns targeting the PowerFlex Manager interface. Implement alerting on account lockouts or repeated authentication attempts using shared or service accounts, as these may precede exploitation.

Why prioritize this

Although not yet on the CISA KEV list, this vulnerability warrants near-term attention due to its HIGH severity rating, the low barrier to exploitation (any authenticated user), and the critical operational role of PowerFlex Manager in storage infrastructure. Organizations should treat this as a priority-high patch candidate within the next 30 days, balancing patch testing and validation against the moderate exploitability risk in the current threat landscape.

Risk score, explained

The CVSS 3.1 score of 7.1 reflects a HIGH severity issue: network-accessible, low-complexity attack requiring only low privileges, with no user interaction needed. The primary impact is denial of service (high availability impact), which directly affects business operations. While confidentiality and integrity are not compromised, the combination of easy exploitability, low privilege barrier, and operational impact justifies the HIGH rating. Organizations with mature patch management and network segmentation may temporarily accept this risk for a controlled patching cycle, but remediation should not be deferred beyond 60 days.

Frequently asked questions

Can this vulnerability be exploited without valid credentials?

No. The vulnerability requires a valid, authenticated user account with low privileges. An attacker must first obtain or compromise credentials to gain remote access to PowerFlex Manager. However, 'low privilege' means the account does not need administrative rights, making the threat surface broader than admin-only flaws.

What versions of PowerFlex Manager are safe?

Version 5.1.0.1 and later are patched. Organizations should verify their exact version and consult Dell's advisory to confirm the minimum safe version. If you are unsure of your current version, check the PowerFlex Manager UI or review deployment documentation.

Is there a workaround if we cannot patch immediately?

Workarounds depend on network architecture and access controls. Consider restricting network access to PowerFlex Manager to trusted administrative networks, limiting which user accounts have access, and enabling detailed logging to detect suspicious activity. However, these are compensating controls, not a substitute for patching. Consult Dell support for any vendor-provided workarounds.

Does this vulnerability allow credential theft or lateral movement?

No. The vulnerability causes denial of service only. It does not enable an attacker to read data, modify configurations, escalate privileges, or move laterally to other systems. However, disruptive attacks may themselves be used as cover for other malicious activity, so investigate any denial-of-service events thoroughly.

This analysis is provided for informational purposes to support cybersecurity decision-making. It reflects publicly available information as of the publish date and does not constitute legal, technical, or compliance advice. Organizations must verify all references, version numbers, and patch guidance against Dell's official security advisories and release notes. Patch testing, rollout timing, and risk acceptance decisions must align with your organization's change management, business continuity, and risk tolerance policies. SEC.co and its contributors assume no liability for the accuracy, completeness, or applicability of this analysis to your specific environment. Source: NVD (public-domain), retrieved 2026-07-27. Analysis generated by SEC.co (claude-haiku-4-5).