PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-46460 Dell CVE debrief

CVE-2026-46460 is an Incorrect Authorization vulnerability in Dell PowerScale OneFS. A low-privileged adjacent network attacker could potentially exploit this vulnerability, leading to unauthorized modification of system logs. The vulnerability affects Dell PowerScale OneFS versions 9.5.0.0 through 9.7.1.15, versions 9.8.0.0 through 9.13.1.0, and versions prior to 9.15.0.0. Defenders should prioritize verifying and applying the vendor's security update, reviewing system logs, and implementing network segmentation to limit attacker access.

Vendor
Dell
Product
PowerScale OneFS
CVSS
LOW 3.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-09
Original CVE updated
2026-09-16
Advisory published
2026-09-09
Advisory updated
2026-09-16

Who should care

Defenders responsible for Dell PowerScale OneFS systems, particularly those with low-privileged adjacent network access, should assess exposure and prioritize verification and remediation.

Why it matters

CVE-2026-46460 is an Incorrect Authorization vulnerability in Dell PowerScale OneFS that could allow a low-privileged adjacent network attacker to modify system logs. Defenders should prioritize verifying and applying the vendor's security update, reviewing system logs, and implementing network segmentation to limit attacker access.

  • Potential unauthorized modification of system logs by a low-privileged adjacent network attacker
  • Need to verify and apply the vendor's security update to prevent exploitation
  • Importance of reviewing system logs for unauthorized modifications
  • Network segmentation may be necessary to limit adjacent network attacker access

Technical summary

Dell PowerScale OneFS, versions 9.5.0.0 through 9.7.1.15, versions 9.8.0.0 through 9.13.1.0, and versions prior to 9.15.0.0, contain an Incorrect Authorization vulnerability. A low privileged adjacent network attacker could potentially exploit this vulnerability, leading to unauthorized modification of system logs. The vulnerability has a CVSS score of 3.5 and is considered to be of low severity. Defenders should prioritize verifying and applying the vendor's security update, reviewing system logs, and implementing network segmentation to limit attacker access.

Defensive priority

Defenders should prioritize verifying and applying the vendor's security update.

Recommended defensive actions

  • Verify and apply the vendor's security update
  • Review system logs for unauthorized modifications
  • Implement network segmentation to limit adjacent network attacker access
  • Monitor for suspicious activity
  • Conduct regular vulnerability assessments
  • Maintain up-to-date incident response plans
  • Review and update security policies

Evidence notes

The CVE record and NVD entry provide details on the vulnerability and affected versions. The vulnerability is considered to be of low severity, with a CVSS score of 3.5. Dell PowerScale OneFS versions 9.5.0.0 through 9.7.1.15, versions 9.8.0.0 through 9.13.1.0, and versions prior to 9.15.0.0 are affected. There is no evidence of public exploitation. Defenders should verify the affected versions and apply the vendor's security update.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-46460 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-46460

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-46460 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-46460

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://www.dell.com/support/kbdoc/en-us/000505684/dsa-2026-360-security-update-for-dell-powerscale-onefs-multiple-vulnerabilities

    [email protected] - Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.