Critical Flaws Found in Dell ObjectScale—Remote Code Execution Risk

Dell has issued a warning for multiple serious security vulnerabilities affecting its ObjectScale and Elastic Cloud Storage (ECS) platforms. The most dangerous resides in ObjectScale versions prior to 4.4.0.0, enabling unauthenticated attackers to execute remote code through an untrusted data deserialization flaw. This issue, labeled CVE-2026-70416, carries a perfect CVSS score of 10.0, indicating maximum severity.

What the Vulnerabilities Are

Beyond CVE-2026-70416, Dell’s advisory highlights several additional weaknesses. One is CVE-2025-43936, an improper authentication bug (rating 8.1) that also impacts ObjectScale before version 4.4.0.0, giving remote attackers unauthorized access without needing valid credentials. Though the exploit is complex, it does not require user interaction, which raises the severity of remote exposure.

Two more significant issues affect both ECS versions 3.8.1.0 through 3.8.1.7 and ObjectiveScale under 4.4.0.0. CVE-2026-26947 involves flawed privilege management, potentially letting privileged local users gain more control—a threat to confidentiality, integrity and availability. Separately, CVE-2025-36591 concerns use of a weak or deprecated cryptographic algorithm, which could let local high-privileged attackers access sensitive information.

Another security concern is CVE-2026-76104, a permissions misconfiguration in the operating system that may allow a remote user possessing high privileges to provoke a denial of service. Dell’s advisory also flags vulnerabilities in third-party components bundled with ObjectScale/ECS—these include flaws in Apache Log4j, liblzma, and the Linux kernel (such as CVE-2026-34477, CVE-2026-34478, CVE-2026-34480, CVE-2026-34743, CVE-2026-31694, CVE-2026-43499).

Who’s Affected & What to Do

All systems running ObjectScale or ECS versions earlier than 4.4.0.0 are at risk. Dell urges users to update to version 4.4.0.0 or later. For those on supported but older releases, upgrading directly to ObjectScale 4.2.0.1 is also allowed. Customers should request an Operating Environment Upgrade under Dell’s advisory DSA-2026-393.

While patches are pending, organizations are advised to follow mitigation steps: secure service-level communications per Dell’s Security Configuration Guide; restrict access to admin and storage-management interfaces to trusted networks; scan for exposed ObjectScale services; monitor for anomalous authentication attempts; and keep alerts on unexpected configuration or permission changes. Dell credits researcher WinD39 (aka Huynh Dinh Vu) with discovering CVE-2026-70416.

This advisory was published on September 10, 2026, under Dell’s tracking number DSA-2026-393. It underscores a shift toward frequent high-impact flaws in core storage systems, particularly where object storage and cloud workloads are concerned.

What This Means and What to Watch For
ObjectScale’s role as enterprise object storage means these vulnerabilities could expose backups, archives, and cloud-native workloads to major risk. The existence of a remote code execution flaw without authentication is especially alarming in environments that lack strict network segmentation or have publicly accessible storage management interfaces. Moving forward, any impact or exploit in the wild of CVE-2026-70416 will be critical to trace, and organizations should prioritize patching. Strong internal monitoring and network isolation remain key defense layers until updates are widely deployed.