PatchSiren cyber security CVE debrief
CVE-2026-46460 Dell CVE debrief
CVE-2026-46460 is an Incorrect Authorization vulnerability in Dell PowerScale OneFS. A low-privileged adjacent network attacker could potentially exploit this vulnerability, leading to unauthorized modification of system logs. The vulnerability affects Dell PowerScale OneFS versions 9.5.0.0 through 9.7.1.15, versions 9.8.0.0 through 9.13.1.0, and versions prior to 9.15.0.0. Defenders should prioritize verifying and applying the vendor's security update, reviewing system logs, and implementing network segmentation to limit attacker access.
- Vendor
- Dell
- Product
- PowerScale OneFS
- CVSS
- LOW 3.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-09
- Original CVE updated
- 2026-09-16
- Advisory published
- 2026-09-09
- Advisory updated
- 2026-09-16
Who should care
Defenders responsible for Dell PowerScale OneFS systems, particularly those with low-privileged adjacent network access, should assess exposure and prioritize verification and remediation.
Why it matters
CVE-2026-46460 is an Incorrect Authorization vulnerability in Dell PowerScale OneFS that could allow a low-privileged adjacent network attacker to modify system logs. Defenders should prioritize verifying and applying the vendor's security update, reviewing system logs, and implementing network segmentation to limit attacker access.
- Potential unauthorized modification of system logs by a low-privileged adjacent network attacker
- Need to verify and apply the vendor's security update to prevent exploitation
- Importance of reviewing system logs for unauthorized modifications
- Network segmentation may be necessary to limit adjacent network attacker access
Technical summary
Dell PowerScale OneFS, versions 9.5.0.0 through 9.7.1.15, versions 9.8.0.0 through 9.13.1.0, and versions prior to 9.15.0.0, contain an Incorrect Authorization vulnerability. A low privileged adjacent network attacker could potentially exploit this vulnerability, leading to unauthorized modification of system logs. The vulnerability has a CVSS score of 3.5 and is considered to be of low severity. Defenders should prioritize verifying and applying the vendor's security update, reviewing system logs, and implementing network segmentation to limit attacker access.
Defensive priority
Defenders should prioritize verifying and applying the vendor's security update.
Recommended defensive actions
- Verify and apply the vendor's security update
- Review system logs for unauthorized modifications
- Implement network segmentation to limit adjacent network attacker access
- Monitor for suspicious activity
- Conduct regular vulnerability assessments
- Maintain up-to-date incident response plans
- Review and update security policies
Evidence notes
The CVE record and NVD entry provide details on the vulnerability and affected versions. The vulnerability is considered to be of low severity, with a CVSS score of 3.5. Dell PowerScale OneFS versions 9.5.0.0 through 9.7.1.15, versions 9.8.0.0 through 9.13.1.0, and versions prior to 9.15.0.0 are affected. There is no evidence of public exploitation. Defenders should verify the affected versions and apply the vendor's security update.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-46460 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-46460
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-46460 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-46460
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.dell.com/support/kbdoc/en-us/000505684/dsa-2026-360-security-update-for-dell-powerscale-onefs-multiple-vulnerabilities
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.