Dell TechnologiesCVE-2026-56690
Dell Technologies PowerFlex Manager: SQL injection
High8.5CVE-2026-56690 · Published Jul 10, 2026 · updated Jul 16, 2026
Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure, Information exposure, and Unauthorized access.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| PowerFlex Manager Product | < 5.1.0.1 or later | 5.1.0.1 or later |
| < 4.5.5.2 or later | 4.5.5.2 or later |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-89
More Dell Technologies advisories
All Dell Technologies| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 10 | Dell Technologies Unisphere for PowerMax: unsafe deserialization | High8.8 | 10.3.0.7 or later+1 more |
| Jul 10 | Dell Technologies Unisphere for PowerMax: XML external entity | Medium5.3 | 10.3.0.7 or later+1 more |
| Jul 10 | Dell Technologies Unisphere for PowerMax: path traversal | Medium6.5 | 10.3.0.7 or later+1 more |
| Jul 10 | Dell Technologies PowerFlex Manager: command injection | Critical9.1 | 5.1.0.1 or later+1 more |
| Jul 10 | Dell Technologies PowerFlex Manager: SQL injection | High7.7 | 5.1.0.1 or later+1 more |
| Jul 8 | Dell Technologies PowerProtect Data Domain: improper authorization | High8.8 | 8.7.0.0 or later+3 more |