← Browse

CVE-2026-35070

Low

No strong exploitation signal.

CVSS base
6.4 MEDIUM
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
0.5%
38.5th percentile
CISA KEV
Not listed
Weakness / dates
CWE-77
Published 2026-05-20 · modified 2026-07-24

CVSS breakdown

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Attack VectorLLocal
Attack ComplexityHHigh
Privileges RequiredHHigh
User InteractionNNone
ScopeUUnchanged
ConfidentialityHHigh
IntegrityHHigh
AvailabilityHHigh

Timeline

Description

Dell SmartFabric Storage Software, versions prior to 1.4.5, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.

Affected

dell

References

Official: NVD · CVE.org