logo

Critical 9.8 Alert: Hard-Coded Credentials in Dell ECS and ObjectScale Leave Filesystems Exposed

ID: 0e0b16e2-065d-5dd1-adb5-6ed5c1fe0962

STIX ID: report--0e0b16e2-065d-5dd1-adb5-6ed5c1fe0962

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Ddos

...
...

Dell released a high-priority advisory for Elastic Cloud Storage (ECS) and ObjectScale addressing multiple vulnerabilities, the most severe being CVE-2026-40636 (CVSS 9.8) due to hard-coded credentials that could allow an unauthenticated local attacker filesystem access; three additional medium-severity flaws affecting privilege elevation, CSV processing, and geo-replication are also patched, and Dell urges customers to upgrade to ObjectScale 4.3.0.0+ and change default credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.