Dell TechnologiesCVE-2026-54469
Dell Technologies Unisphere for PowerMax: unsafe deserialization
High8.8CVE-2026-54469 · Published Jul 10, 2026 · updated Jul 16, 2026
Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Deserialization of Untrusted Data vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Unisphere for PowerMax Product | < 10.3.0.7 or later | 10.3.0.7 or later |
| < 10.3.1.1 Patch 11360 or later | 10.3.1.1 Patch 11360 or later |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-502
- www.cve.org/CVERecord?id=CVE-2026-54469
- nvd.nist.gov/vuln/detail/CVE-2026-54469
- www.dell.com/support/kbdoc/en-us/000483543/dsa-2026-272-dell-powermaxos-dell-powermax-eem-dell-unisphere-for-powermax-dell-unisphere-for-powermax-virtualappliance-dell-unisphere-360-dell-solutionsenabler-and-dell-solutionsenabler-virtualappliance-security-update-for-multiple-vulnerabilities
More Dell Technologies advisories
All Dell Technologies| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 10 | Dell Technologies Unisphere for PowerMax: XML external entity | Medium5.3 | 10.3.0.7 or later+1 more |
| Jul 10 | Dell Technologies Unisphere for PowerMax: path traversal | Medium6.5 | 10.3.0.7 or later+1 more |
| Jul 10 | Dell Technologies PowerFlex Manager: command injection | Critical9.1 | 5.1.0.1 or later+1 more |
| Jul 10 | Dell Technologies PowerFlex Manager: SQL injection | High7.7 | 5.1.0.1 or later+1 more |
| Jul 10 | Dell Technologies PowerFlex Manager: SQL injection | High8.5 | 5.1.0.1 or later+1 more |
| Jul 8 | Dell Technologies PowerProtect Data Domain: improper authorization | High8.8 | 8.7.0.0 or later+3 more |