Critical 9.8 Alert: Hard-Coded Credentials in Dell ECS and ObjectScale Leave Filesystems Exposed
ID: 0e0b16e2-065d-5dd1-adb5-6ed5c1fe0962
STIX ID: report--0e0b16e2-065d-5dd1-adb5-6ed5c1fe0962
Feed Name: securityonline.info
Dell released a high-priority advisory for Elastic Cloud Storage (ECS) and ObjectScale addressing multiple vulnerabilities, the most severe being CVE-2026-40636 (CVSS 9.8) due to hard-coded credentials that could allow an unauthenticated local attacker filesystem access; three additional medium-severity flaws affecting privilege elevation, CSV processing, and geo-replication are also patched, and Dell urges customers to upgrade to ObjectScale 4.3.0.0+ and change default credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
