Skip to content
Dell TechnologiesCVE-2026-56690

Dell Technologies PowerFlex Manager: SQL injection

High8.5CVE-2026-56690 · Published Jul 10, 2026 · updated Jul 16, 2026

Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure, Information exposure, and Unauthorized access.

Dell Technologies advisory

Affected versions

PackageAffectedFixed in
PowerFlex Manager
Product
< 5.1.0.1 or later5.1.0.1 or later
< 4.5.5.2 or later4.5.5.2 or later
Details and references

More Dell Technologies advisories

All Dell Technologies
Advisory
Dell Technologies Unisphere for PowerMax: unsafe deserialization
High8.8Jul 10
Dell Technologies Unisphere for PowerMax: XML external entity
Medium5.3Jul 10
Dell Technologies Unisphere for PowerMax: path traversal
Medium6.5Jul 10
Dell Technologies PowerFlex Manager: command injection
Critical9.1Jul 10
Dell Technologies PowerFlex Manager: SQL injection
High7.7Jul 10
Dell Technologies PowerProtect Data Domain: improper authorization
High8.8Jul 8

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.