Dell TechnologiesCVE-2026-54489
Dell Technologies Virtual Storage Integrator: information disclosure
Critical9.1CVE-2026-54489 · Published Aug 6, 2026 · updated Aug 7, 2026
Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session hijacking. This vulnerability is considered critical as it allows an unauthenticated attacker to obtain active session credentials and fully impersonate authenticated users, including administrators. Dell recommends customers to upgrade at the earliest opportunity.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Virtual Storage Integrator for VMware vSphere Client Product | < 10.11.1.0 or later | 10.11.1.0 or later |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-200
More Dell Technologies advisories
All Dell Technologies| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 7 | Dell OpenManage Server Administrator Managed Node: path traversal | Medium6.5 | 11.1.0.2+2 more |
| Aug 7 | Dell OpenManage Server Administrator Managed Node: improper authentication | High7.7 | OpenManage Server Administrator Managed Node (Patch) for...+2 more |
| Aug 6 | Dell Technologies Virtual Storage Integrator: command injection | Critical9.8 | 10.11.1.0 or later |
| Aug 6 | Dell Technologies RVTools: improper certificate validation | Medium6.8 | 4.8.1 or later |
| Aug 3 | Dell Technologies Display and Peripheral Manager: improper access control | High7.8 | 2.3.0.1005 |
| Aug 3 | Dell Technologies Display and Peripheral Manager: missing authentication | High7.8 | 2.3.0.1005 |