Skip to content
Dell TechnologiesCVE-2026-54470

Dell Technologies Unisphere for PowerMax: XML external entity

Medium5.3CVE-2026-54470 · Published Jul 10, 2026 · updated Jul 16, 2026

Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

Dell Technologies advisory

Affected versions

PackageAffectedFixed in
Unisphere for PowerMax
Product
< 10.3.0.7 or later10.3.0.7 or later
< 10.3.1.1 Patch 11360 or later10.3.1.1 Patch 11360 or later
Details and references

More Dell Technologies advisories

All Dell Technologies
Advisory
Dell Technologies Unisphere for PowerMax: unsafe deserialization
High8.8Jul 10
Dell Technologies Unisphere for PowerMax: path traversal
Medium6.5Jul 10
Dell Technologies PowerFlex Manager: command injection
Critical9.1Jul 10
Dell Technologies PowerFlex Manager: SQL injection
High7.7Jul 10
Dell Technologies PowerFlex Manager: SQL injection
High8.5Jul 10
Dell Technologies PowerProtect Data Domain: improper authorization
High8.8Jul 8

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.