MEDIUM 6.5

CVE-2026-54468: Dell Unisphere for PowerMax Path Traversal Vulnerability

Dell Unisphere for PowerMax versions 10.3.0.5 and earlier contain a flaw that allows an authenticated attacker with basic network access to bypass file path restrictions and read files they should not be able to access. The vulnerability requires valid credentials but does not need user interaction to trigger, making it a concern for organizations with untrusted internal users or compromised service accounts.

Source data · NVD / CISA · public domain

CVSS
3.1 · 6.5 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weaknesses (CWE)
CWE-22
Affected products
1 configuration(s)
Published / Modified
2026-07-10 / 2026-07-16

NVD description (verbatim)

Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a path traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability to read arbitrary files.

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-54468 is a path traversal vulnerability (CWE-22) in Dell Unisphere for PowerMax management software affecting version 10.3.0.5 and prior releases. The flaw enables a low-privileged remote authenticated user to construct file path requests that traverse directory boundaries, allowing arbitrary file read access. The attack vector is network-based with low attack complexity, and no user interaction is required. The vulnerability results in high confidentiality impact while maintaining the integrity and availability of the system.

Business impact

A successful exploitation could expose sensitive configuration files, credentials, or business data stored on the Unisphere management system. Organizations operating PowerMax storage arrays rely on Unisphere for administrative control; unauthorized file access could reveal storage architecture details, authentication tokens, or customer metadata. This is particularly concerning in multi-tenant or compliance-heavy environments where data segregation is a control requirement.

Affected systems

Dell Unisphere for PowerMax version 10.3.0.5 and all earlier versions are vulnerable. Organizations should verify their deployed Unisphere versions immediately. If you are running version 10.3.0.6 or later, you are not affected by this specific vulnerability; verify against Dell's advisory for the exact remediation version number.

Exploitability

Exploitation requires a valid user account with remote network access to the Unisphere management interface—either a legitimate account, a compromised credential, or an insider threat. The attack does not require elevated privileges, making it accessible to lower-tier service accounts. While this raises the bar compared to unauthenticated exploits, the low complexity and lack of user interaction requirement means exploitation can be automated once credentials are obtained. This vulnerability is not currently tracked in the CISA Known Exploited Vulnerabilities catalog.

Remediation

Dell has released a patched version addressing this vulnerability. Organizations must upgrade Unisphere for PowerMax to a version after 10.3.0.5. Verify the specific remediation version number against Dell's official security advisory. Until patching is possible, implement network-level access controls to restrict Unisphere management interface exposure to authorized administrative networks and monitor for suspicious file access patterns.

Patch guidance

Coordinate with your storage infrastructure team to schedule a Unisphere upgrade during a maintenance window. Dell typically provides clear upgrade paths in their advisory. Test the patch in a non-production environment first to ensure compatibility with your PowerMax configuration and any custom integrations. After upgrade, verify that administrative credentials are rotated and that any accounts with unusual activity are reviewed.

Detection guidance

Monitor Unisphere logs for file access requests with path traversal sequences (e.g., multiple ../ patterns in request paths or file references outside expected directories). Audit authentication logs for failed or successful login attempts by service accounts outside normal business hours or geographic locations. Network IDS/IPS signatures for path traversal patterns in HTTP requests to the Unisphere management port may help identify reconnaissance or exploitation attempts.

Why prioritize this

This vulnerability scores MEDIUM (6.5 CVSS) and requires authentication, which prevents it from being automatically exploitable across the internet by anonymous actors. However, the high confidentiality impact and low complexity make it an attractive target for insiders or attackers who have obtained credentials through phishing, default passwords, or lateral movement. Prioritize patching if Unisphere is Internet-facing, if service accounts have weak passwords, or if you operate in a compliance domain where unauthorized file access is a reportable breach. For isolated, air-gapped Unisphere instances with strict access control, the risk is lower but should still be addressed in regular maintenance cycles.

Risk score, explained

The CVSS 3.1 score of 6.5 reflects the authentication requirement (PR:L), network accessibility (AV:N), and direct impact on confidentiality (C:H) with no changes to system integrity or availability. The score appropriately classifies this as MEDIUM severity rather than HIGH or CRITICAL, signaling that while it is exploitable and damaging, it is not an emergency requiring immediate shutdown of services. Risk context matters: the same score carries higher business risk in zero-trust environments or those with a history of insider threats.

Frequently asked questions

Do I need to patch immediately if Unisphere is only accessible from our internal management network?

While internal access does reduce attacker reach, the vulnerability can still be exploited by insiders or by external attackers who have gained internal network access. If your Unisphere system is segmented behind a firewall and accessed only by a small trusted team, you may have a longer remediation window—but should not delay indefinitely. Verify your access controls and include this in your regular patch cycle within 60–90 days.

What should I do if I suspect someone has exploited this vulnerability?

Review Unisphere authentication logs for unauthorized login events and check file access logs for suspicious path traversal requests. Cross-reference with your change management records to identify whether any unexpected reads occurred. If breach is suspected, engage your incident response team and consider resetting all Unisphere service account credentials and reviewing what files might have been accessed. Also audit connected PowerMax systems for any unauthorized configuration changes.

Will upgrading Unisphere require downtime to my storage arrays?

Upgrading Unisphere management software typically does not require storage array downtime, as Unisphere is a management tool separate from the array itself. However, administrative operations will be unavailable during the upgrade. Coordinate with your storage team and schedule during a maintenance window when administrative tasks can be deferred. Dell's upgrade documentation will specify any prerequisites or compatibility checks needed before upgrade.

How can I tell what version of Unisphere I am running?

Log into the Unisphere web interface and check the version number in the Help or About menu, or consult your system documentation. You can also run the Unisphere installation commands or query the system directly via SSH if you have administrative access. If unsure, contact your storage administrator or Dell support to confirm your current version and remediation path.

This analysis is provided for informational purposes and reflects the state of the vulnerability as publicly disclosed. Organizations should verify all patch versions, affected systems, and remediation steps against Dell's official security advisories before taking action. Testing should be performed in non-production environments. SEC.co does not provide warranty or guarantee regarding the completeness or accuracy of third-party vendor information. Consult with your IT and security teams to assess risk in your specific environment. Source: NVD (public-domain), retrieved 2026-08-17. Analysis generated by SEC.co (claude-haiku-4-5).