Summary
| Parameter | Value |
|---|---|
| CVE ID | CVE-2026-79687 |
| Alert Source | GitHub Advisory - Critical Vulnerability |
| CVE Publication Year | 2026 |
| Date Published | 2026-09-01 |
| Vendor | Dell |
| Product | PowerStore |
| CVSS Score | 9.0 (critical) |
| EPSS Score | No data |
| CISA KEV | No |
| Ransomware | Not confirmed |
Vulnerability Description
The SDNAS (Software Defined NAS) component of the Dell PowerStore array contains a Missing Authentication for Critical Function vulnerability - a critical function is reachable without verifying the caller’s identity.
An unauthenticated attacker with remote network access to the array can exploit it to gain filesystem access. In practice this means the ability to read, and potentially modify, data stored on the NAS volumes the array serves.
The severity here comes not from technical complexity but from what is being protected. A PowerStore array typically holds departmental file shares, virtual machine repositories and - frequently - the backup repository. Bypassing access control at this layer simultaneously bypasses the NTFS/NFS permissions defined higher in the stack.
Required Actions
- Install the PowerStoreOS fix named in Dell’s security advisory (DSA) for CVE-2026-79687. Confirm the affected version range in the advisory - Dell publishes it per PowerStoreOS branch.
- Restrict network access to management interfaces and SDNAS services. The array should not be reachable from user networks or lower-trust segments - its place is a dedicated storage/management network.
- Verify the array is not internet-reachable. Check edge NAT and firewall rules for any published array services.
- Review share access logs for operations that cannot be tied to a user account or client host.
- Verify backup immutability. If PowerStore hosts a backup repository, confirm copies are covered by immutability and that retention has not been modified.
- Bring the array into your vulnerability management cycle. Storage systems are often excluded from scanning - a systematic gap in most vulnerability management programmes rather than a one-off oversight.
Who Is Affected?
Organisations operating Dell PowerStore arrays with SDNAS enabled (SMB/NFS file share services).
PowerStore is among the more common storage platforms in mid-to-large Polish enterprises - banking, insurance, industry and public administration - usually as the primary production array. Deployments using block access only (iSCSI/FC) without SDNAS configured are less exposed, though patching remains advisable.
Pay particular attention where the array serves both production and the backup repository - it then becomes a single point whose compromise invalidates the recovery plan.
Sources
Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.
