Skip to content
Dell TechnologiesCVE-2026-56689

Dell Technologies PowerFlex Manager: SQL injection

High7.7CVE-2026-56689 · Published Jul 10, 2026 · updated Jul 16, 2026

Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.

Dell Technologies advisory

Affected versions

PackageAffectedFixed in
PowerFlex Manager
Product
< 5.1.0.1 or later5.1.0.1 or later
< 4.5.5.2 or later4.5.5.2 or later
Details and references

More Dell Technologies advisories

All Dell Technologies
Advisory
Dell Technologies Unisphere for PowerMax: unsafe deserialization
High8.8Jul 10
Dell Technologies Unisphere for PowerMax: XML external entity
Medium5.3Jul 10
Dell Technologies Unisphere for PowerMax: path traversal
Medium6.5Jul 10
Dell Technologies PowerFlex Manager: command injection
Critical9.1Jul 10
Dell Technologies PowerFlex Manager: SQL injection
High8.5Jul 10
Dell Technologies PowerProtect Data Domain: improper authorization
High8.8Jul 8

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.