MEDIUM 5.7

CVE-2026-35067: Dell PowerFlex Manager Privilege Escalation Vulnerability

Dell PowerFlex Manager versions before 5.1.0.1 contain a flaw in how access is controlled that could allow someone already on your network with limited user privileges to gain higher-level administrative access or view sensitive data they shouldn't see. An attacker would need to be on the same network segment as the system and have at least basic user credentials to attempt this attack.

Source data · NVD / CISA · public domain

CVSS
3.1 · 5.7 MEDIUM · CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weaknesses (CWE)
CWE-284
Affected products
1 configuration(s)
Published / Modified
2026-06-17 / 2026-06-25

NVD description (verbatim)

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Elevation of privileges and Unauthorized access.

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-35067 is an improper access control vulnerability (CWE-284) in Dell PowerFlex Manager affecting versions prior to 5.1.0.1. The vulnerability allows a low-privileged, authenticated attacker with adjacent network access to bypass authorization controls and escalate privileges or gain unauthorized information disclosure. The CVSS 3.1 score of 5.7 (MEDIUM) reflects local/adjacent network attack surface, low complexity, requirement for low privilege level, and high confidentiality impact without integrity or availability impact.

Business impact

If exploited, this vulnerability could enable insider threats or compromised user accounts to escalate to storage administrator roles within PowerFlex Manager, potentially exposing block storage configurations, performance data, or enabling unauthorized modifications to storage policies. For organizations running Dell PowerFlex infrastructure, this represents a lateral movement risk post-breach and could complicate compliance audits if administrative activity logs are accessed by unauthorized users.

Affected systems

Dell PowerFlex Manager versions prior to 5.1.0.1 are affected. Organizations should identify all instances of PowerFlex Manager in their environment and compare against the patched version threshold. This includes both on-premises and hybrid deployments using affected version lines.

Exploitability

Exploitation requires three conditions: (1) the attacker must already possess valid user credentials and be authenticated, (2) the attacker must have network connectivity to the PowerFlex Manager instance (adjacent network access), and (3) the target system must be running an unpatched version prior to 5.1.0.1. This is not a remote unauthenticated attack. The vulnerability has not been added to CISA's Known Exploited Vulnerabilities catalog, suggesting in-the-wild exploitation has not yet been publicly documented.

Remediation

Upgrade Dell PowerFlex Manager to version 5.1.0.1 or later. Before upgrading, review Dell's official security advisory and patch release notes to understand any configuration changes, compatibility notes, or pre-upgrade validation steps. Test patches in a non-production environment that mirrors your storage configuration. Plan maintenance windows in coordination with storage operations teams.

Patch guidance

Contact Dell Support or consult Dell's security advisories for the specific upgrade path for your PowerFlex Manager deployment. Verify the exact version number of your current installation through the management console or administrative interface. Dell may provide staged releases or phased deployment guidance; follow their recommended sequence. After patching, confirm the new version number is reflected in system information and run any post-upgrade validation tests to ensure storage services remain operational.

Detection guidance

Monitor PowerFlex Manager access logs for: (1) failed authentication attempts from internal network addresses, (2) privilege escalation events (users transitioning from standard to admin roles without corresponding administrative requests), (3) access to sensitive configuration endpoints by low-privileged accounts, and (4) anomalous API calls from authenticated sessions with atypical behavior patterns. Enable detailed audit logging if not already active, and correlate PowerFlex logs with identity and access management (IAM) systems to detect compromised credentials being used against storage infrastructure.

Why prioritize this

Although the CVSS score is moderate (5.7), this vulnerability poses meaningful risk in environments where PowerFlex Manager is critical to storage availability and where internal threat vectors are realistic (e.g., after ransomware compromise or employee departure scenarios). The requirement for valid credentials and adjacent access limits broad attack surface, but insider or lateral-movement exploits are plausible. Prioritize based on: (1) whether your PowerFlex Manager is internet-accessible or only internal, (2) the sensitivity of data stored on managed arrays, (3) the number of users with credentials to the system, and (4) your organization's maturity in detecting lateral movement.

Risk score, explained

The CVSS 3.1 score of 5.7 (MEDIUM) reflects a low overall attack complexity and low privilege requirement, but factors in the requirement for adjacent network access (not remote exploitable) and lack of availability or integrity impact—only confidentiality is affected. This scoring appropriately signals that while the vulnerability is not critical, it is material enough to warrant timely patching, particularly for organizations with sensitive storage environments or strict data governance requirements.

Frequently asked questions

Do we need to patch immediately, or can this wait until our next maintenance window?

This is not a critical vulnerability, so you can schedule patching within your normal change management cycle if that cycle is within the next 30–60 days. However, if you are currently in a high-risk posture (e.g., known insider threats, active breach response, or high-value data on the PowerFlex arrays), prioritize an expedited patch deployment.

Can we mitigate this without patching?

Partially. Implement or enforce network segmentation to restrict access to PowerFlex Manager to trusted administrative networks only. Use identity-based access controls (RBAC) to minimize the number of low-privileged accounts with any access to PowerFlex Manager. Monitor administrative logs closely for suspicious privilege escalation. However, these are compensating controls, not fixes—patching is the recommended remediation.

Does this affect our backup or disaster recovery systems if they integrate with PowerFlex Manager?

Potentially, if your backup or DR infrastructure uses a low-privileged service account to communicate with PowerFlex Manager. If exploited, an attacker could theoretically escalate to admin and interfere with backup job policies. After patching, verify that integrated systems (backup appliances, replication engines, etc.) continue to function correctly.

How do we know if we've been exploited?

Review PowerFlex Manager audit logs for: (1) unexpected privilege escalation events, (2) configuration changes made by low-privileged accounts or service principals, (3) new administrative user accounts created without authorization, or (4) access to sensitive endpoints from atypical internal IP addresses. If your organization has experienced a broader breach (phishing, credential compromise), assume attackers may have attempted this exploit and investigate accordingly.

This analysis is provided for informational purposes and reflects publicly available information as of the CVE publication date. Organizations must verify all technical details, patch availability, and compatibility notes directly with Dell's official security advisories and documentation. SEC.co does not perform vulnerability testing and does not provide exploit code or weaponized proof-of-concept materials. Patching should be performed in accordance with your organization's change management and testing policies. The absence of CISA KEV status does not guarantee the absence of threat actor interest; maintain vigilance in monitoring for exploitation attempts. Source: NVD (public-domain), retrieved 2026-07-27. Analysis generated by SEC.co (claude-haiku-4-5).