Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN887
_____________________________________________________________________

DATE                : 15/09/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Dell ObjectScale, Elastic Cloud
                          Storage (ECS) versions prior to 4.4.0.0.
 
=====================================================================
https://www.dell.com/support/kbdoc/en-pk/000505935/dsa-2026-393-security-update-for-dell-objectscale-multiple-vulnerabilities
_____________________________________________________________________


DSA-2026-393: Security update for Dell ObjectScale Multiple
Vulnerabilities

Summary: Dell ObjectScale remediation is available for multiple
security vulnerabilities that could be exploited by malicious users
to compromise the affected system.


Impact

Critical


Details
Third-party Component 	CVEs 	More Information

Apache Log4j 	CVE-2026-34477, CVE-2026-34478, CVE-2026-34480
https://nvd.nist.gov/vuln/search 

liblzma  	CVE-2026-34743 
https://nvd.nist.gov/vuln/search 

Linux Kernel 	CVE-2026-31694, CVE-2026-43499
https://nvd.nist.gov/vuln/search


Proprietary Code CVEs     Description    CVSS Base Score
CVSS Vector String

CVE-2026-70416 	Dell ObjectScale, versions prior to 4.4.0.0,
contains a Deserialization of Untrusted Data vulnerability.
An unauthenticated attacker with remote access could potentially
exploit this vulnerability, leading to Remote execution.
10.0 	CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H 

CVE-2025-43936 	Dell ObjectScale, versions prior to ObjectScale
4.4.0.0, contains an Improper Authentication vulnerability. An
unauthenticated attacker with remote access could potentially
exploit this vulnerability, leading to Unauthorized access.
8.1 	CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H 

CVE-2026-26947 	Dell ECS versions 3.8.1.0 through 3.8.1.7, and
Dell ObjectScale versions prior to 4.4.0.0, contains an
Improper Privilege Management vulnerability. A high privileged
attacker with local access could potentially exploit this
vulnerability, leading to Elevation of privileges. 	6.7
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H 

CVE-2026-76104 	Dell ObjectScale, versions prior to 4.4.0.0,
contains an Incorrect Permission Assignment for Critical
Resource vulnerability in the OS. A high privileged attacker
with remote access could potentially exploit this vulnerability,
leading to Denial of service. 	5.5
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H 

CVE-2025-36591 	Dell ECS versions 3.8.1.0 through 3.8.1.7, and
Dell ObjectScale versions prior to 4.4.0.0, contains an Use of
a Broken or Risky Cryptographic Algorithm vulnerability. A
high privileged attacker with local access could potentially
exploit this vulnerability, leading to Information exposure.
4.4 	CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N 

Dell Technologies recommends all customers consider both the
CVSS base score and any relevant temporal and environmental
scores that may impact the potential severity associated with
a particular security vulnerability.


Affected Products & Remediation

Product    Affected Versions    Remediated Versions   Link
 
Elastic Cloud Storage (ECS) 	Versions 3.x through 3.8.1.7
Version 4.4.0.0 or later 	Open a Service Request for an
Operating Environment Upgrade and Quote DSA-2026-393

ObjectScale 	Versions prior to 4.4.0.0 	Open a Service
Request for an Operating Environment Upgrade and Quote
DSA-2026-393

Note: 

    Customers on any supported affected versions/releases listed
in the ‘Affected Products and Remediation’ section may also
upgrade directly to the 4.4.0.0 release.

    Dell recommends all customers have their ObjectScale systems
upgraded at the earliest opportunity by opening an “Operating
Environment Upgrade” Service Request. 

    Please visit the Security Update Release Schedule for Supported
Versions of ObjectScale (formerly ECS) for more information. 


Workarounds & Mitigations

CVE ID                 Workaround and Mitigation

CVE-2025-43936      Refer to the Secure Service-Level
Communication section in the official "Security
Configuration Guide" 


Revision History

Revision	Date	Description
1.0	2026-09-10	Initial Release
2.0	2026-09-11	Minor updates
3.0	2026-09-14	Minor changes - correction on text


Acknowledgements

CVE-2026-70416: Dell would like to thank WinD39 - Huynh Dinh
Vu for reporting this issue.


Related Information

Dell Security Advisories and Notices
Dell Vulnerability Response Policy
CVSS Scoring Guide


Legal Disclaimer

The information in this Dell Technologies Security Advisory
should be read and used to assist in avoiding situations that
may arise from the problems described herein. Dell Technologies
distributes Security Advisories to bring important security
information to the attention of users of the affected
product(s). Dell Technologies assesses the risk based on an
average of risks across a diverse set of installed systems
and may not represent the actual risk to your local
installation and individual environment. It is recommended
that all users determine the applicability of this information
to their individual environments and take appropriate actions.
The information set forth herein is provided "as is" without
warranty of any kind. Dell Technologies expressly disclaims
all warranties, either express or implied, including the
warranties of merchantability, fitness for a particular
purpose, title and non-infringement. In no event shall Dell
Technologies, its affiliates or suppliers, be liable for any
damages whatsoever arising from or related to the information
contained herein or actions that you decide to take based
thereon, including any direct, indirect, incidental,
consequential, loss of business profits or special damages,
even if Dell Technologies, its affiliates or suppliers have
been advised of the possibility of such damages. Some states
do not allow the exclusion or limitation of liability for
consequential or incidental damages, so the foregoing limitation
shall apply to the extent permissible under law.


Affected Products

ECS, ObjectScale, ECS Appliance, ECS Appliance Hardware Series,
ECS Appliance Software with Encryption, ECS Appliance Software
without Encryption, ObjectScale Software with Encryption,
ObjectScale Software without Encryption , ObjectScale Appliance
Series, ObjectScale Software Series

=========================================================

+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




