PatchSiren cyber security CVE debrief
CVE-2026-32804 Dell CVE debrief
CVE-2026-32804 is a HIGH-severity vulnerability in Dell PowerFlex Manager, with a CVSS score of 8.1. It allows unauthenticated attackers with adjacent network access to gain unauthorized access. Dell has released a security update to address this issue. Organizations using affected versions should prioritize patching. The vulnerability was published on June 17, 2026, and updated on June 18, 2026.
- Vendor
- Dell
- Product
- PowerFlex
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-17
- Original CVE updated
- 2026-06-25
- Advisory published
- 2026-06-17
- Advisory updated
- 2026-06-25
Who should care
Administrators and security teams responsible for Dell PowerFlex Manager systems, especially those with exposed or internet-facing deployments, should be aware of this vulnerability and take immediate action to mitigate potential risks.
Technical summary
The CVE-2026-32804 vulnerability is caused by an Improper Authentication mechanism in Dell PowerFlex Manager. This allows an unauthenticated attacker with adjacent network access to potentially exploit the vulnerability, leading to unauthorized access. The CVSS vector is CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H, indicating a high severity level.
Defensive priority
High
Recommended defensive actions
- Apply the security update provided by Dell (see ref-4) as soon as possible.
- Restrict network access to PowerFlex Manager systems to only trusted users and networks.
- Implement additional authentication mechanisms for accessing PowerFlex Manager.
- Regularly review and update PowerFlex Manager systems to ensure they are running the latest software versions.
- Monitor PowerFlex Manager systems for suspicious activity and implement intrusion detection systems.
Evidence notes
The information provided is based on data from official sources, including the CVE.org record and the NVD detail page. The vendor, Dell, has also provided a security alert regarding this vulnerability. However, the exact versions of PowerFlex Manager affected are not specified in the provided data.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-32804 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-32804
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-32804 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-32804
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.dell.com/support/kbdoc/en-us/000477538/dsa-2026-066-security-update-for-powerflex-software-multiple-vulnerabilities
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.