CVE-2026-35069: Dell PowerFlex Manager SQL Injection Vulnerability – Remediation Guide
Dell PowerFlex Manager versions before 5.1.0.1 contain a SQL injection flaw that allows a low-privileged attacker on the same network to inject malicious SQL commands. This could enable script injection attacks, potentially compromising data confidentiality or system integrity depending on the attacker's follow-up actions. The vulnerability requires adjacent network access and valid credentials to exploit, which limits its immediate exposure but remains a real risk in internal environments.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 5.7 MEDIUM · CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Weaknesses (CWE)
- CWE-89
- Affected products
- 1 configuration(s)
- Published / Modified
- 2026-06-17 / 2026-06-25
NVD description (verbatim)
Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Script injection.
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-35069 is a SQL injection vulnerability (CWE-89) in Dell PowerFlex Manager affecting versions prior to 5.1.0.1. The flaw exists in a component that fails to properly sanitize or parameterize user-controlled input before constructing SQL queries. An adjacent-network attacker with low-privilege credentials can craft malicious SQL payloads to break out of intended query logic and execute arbitrary SQL commands. This can lead to script injection, potentially allowing retrieval or manipulation of sensitive data, authentication bypass, or lateral movement within the PowerFlex infrastructure. The CVSS 3.1 score of 5.7 (MEDIUM) reflects the requirement for authentication and adjacent network access, but the high confidentiality impact indicates that successful exploitation exposes sensitive information.
Business impact
PowerFlex Manager handles storage infrastructure orchestration and configuration in Dell enterprise environments. A successful SQL injection attack could allow an insider or adjacent-network attacker to exfiltrate storage credentials, access management metadata, or manipulate storage policies. In multi-tenant or highly regulated environments, unauthorized data access could trigger compliance violations and customer notifications. The attack also creates a stepping stone for lateral movement into the broader storage fabric. While the immediate blast radius is constrained by network proximity and authentication requirements, the sensitivity of storage management systems elevates business risk beyond the base CVSS score.
Affected systems
Dell PowerFlex Manager versions prior to 5.1.0.1 are affected. Organizations running PowerFlex Manager should verify their installed version immediately. The vulnerability does not affect later versions; verify against the vendor advisory for precise version boundaries and any interim patches applied to your deployment.
Exploitability
Exploitation requires adjacent network access and valid low-privilege credentials—not internet-reachable attack surface. This significantly reduces drive-by exploitation risk but elevates risk for disgruntled employees or lateral movement by an attacker already inside the network perimeter. The CVSS vector (AV:A/PR:L/AC:L) indicates adjacent scope and low complexity, meaning once an attacker has network access and credentials, the attack is straightforward to execute. No public exploit code or widespread weaponization has been reported, and the vulnerability is not on CISA's Known Exploited Vulnerabilities (KEV) catalog.
Remediation
Upgrade Dell PowerFlex Manager to version 5.1.0.1 or later. If immediate patching is not feasible, restrict network access to PowerFlex Manager administrative interfaces to trusted networks and enforce strong authentication policies (MFA where possible). Review access logs for any signs of suspicious SQL queries or unusual administrative activity.
Patch guidance
Dell has released version 5.1.0.1 or later to address this vulnerability. Verify the exact version number against the Dell security advisory for your specific PowerFlex deployment. Test patches in a non-production environment before rolling out to production management clusters to ensure compatibility with your storage infrastructure. Plan patching during a maintenance window to minimize operational disruption to storage services.
Detection guidance
Monitor PowerFlex Manager logs for SQL syntax errors, unusual query patterns, or failed SQL statements—signs of injection attempts. Look for abnormal database connection behavior, unexpected credential access, or authentication anomalies in administrative access logs. If your environment supports it, enable SQL query auditing to capture full command text. Network-based detection should focus on adjacent-network traffic to PowerFlex Manager ports for suspicious payloads containing SQL keywords or special characters.
Why prioritize this
Although the CVSS score is MEDIUM (5.7), prioritize this vulnerability for organizations with PowerFlex Manager in production. The high confidentiality impact and the sensitive nature of storage management systems justify urgent attention. The authentication and adjacency requirements reduce external risk, but the ease of exploitation (low AC) and potential for insider threats argue for swift patching. Organizations should treat this as a high-priority internal infrastructure security issue.
Risk score, explained
CVSS 3.1 score of 5.7 (MEDIUM) is driven by: high confidentiality impact (C:H) reflecting potential unauthorized access to sensitive storage data; adjacent network requirement (AV:A) limiting exposure to internal or same-network attackers; low-privilege authentication requirement (PR:L) narrowing the attacker pool; and low attack complexity (AC:L) indicating straightforward exploitation once prerequisites are met. No integrity or availability impact is scored, but script injection could enable secondary attacks. The score appropriately reflects a significant but not critical risk for networked deployments.
Frequently asked questions
Does this vulnerability affect my PowerFlex deployment if I'm running version 5.1.0.1 or later?
No. This vulnerability affects only versions prior to 5.1.0.1. If you are running 5.1.0.1 or any version released after it, you are not affected. Verify your exact version number in the PowerFlex Manager administrative console or via Dell support.
Can this vulnerability be exploited over the internet?
No. The vulnerability requires adjacent network access, meaning the attacker must be on the same network segment or have internal access. It cannot be exploited remotely from the internet, but it remains a meaningful risk for insider threats or compromised internal systems.
What should I do if I cannot patch immediately?
Restrict access to PowerFlex Manager to trusted administrative networks only. Use network segmentation and firewall rules to limit connectivity. Enforce strong authentication (MFA if available) and monitor administrative access logs for anomalous activity. Plan a patching timeline as soon as feasible.
Is there a public exploit for this vulnerability?
No public exploit code has been released, and the vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog. However, SQL injection is a well-understood attack vector; do not assume the vulnerability will remain unexploited indefinitely. Patch as soon as your maintenance window allows.
This analysis is provided for informational purposes and reflects publicly available information as of the publication date. Organizations should verify all patch versions, compatibility matrices, and deployment guidance against official Dell security advisories and their internal change management processes. SEC.co makes no warranties regarding the completeness or accuracy of this analysis. Always consult with Dell support and conduct thorough testing in non-production environments before deploying patches to production systems. Security decisions should incorporate your organization's specific risk profile, network architecture, and compliance requirements. Source: NVD (public-domain), retrieved 2026-07-27. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-35068LOWDell PowerFlex Manager SQL Injection Vulnerability – Security Analysis
- CVE-2026-0075MEDIUMAndroid SQL Injection in Contacts Database – Privilege Escalation Risk
- CVE-2026-10039MEDIUMFrontend Admin WordPress Plugin SQL Injection Vulnerability
- CVE-2026-10155MEDIUMSQL Injection in Bdtask Multi-Store Inventory Management System 1.0
- CVE-2026-10170MEDIUMSQL Injection in code-projects Visitor Management System 1.0
- CVE-2026-10171MEDIUMSQL Injection in code-projects Online Music Site 1.0 AdminUpdateAlbum.php
- CVE-2026-10176MEDIUMSQL Injection in Aider-AI Aider 0.86.3 Code Generation
- CVE-2026-10193MEDIUMSQL Injection in OFCMS ComnController – Authentication Required