CVE Vulnerabilities

CVE-2026-21425

Incorrect Privilege Assignment

Published: Mar 04, 2026 | Modified: Mar 04, 2026
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Dell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an incorrect privilege assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

Weakness

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
Powerscale_onefsDell*9.10.1.6 (excluding)
Powerscale_onefsDell9.11.0.0 (including)9.13.0.0 (excluding)

Potential Mitigations

References