Dell Technologies Virtual Storage Integrator: command injection
Critical9.8CVE-2026-67261 · Published Aug 6, 2026 · updated Aug 7, 2026
Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying operating system with root privileges. Exploitation may lead to a complete system takeover by an attacker. This vulnerability is considered critical as it allows an unauthenticated remote attacker to achieve arbitrary code execution as root, potentially compromising the entire VSI deployment and underlying infrastructure. Dell recommends customers to upgrade at the earliest opportunity.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Virtual Storage Integrator for VMware vSphere Client Product | < 10.11.1.0 or later | 10.11.1.0 or later |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-78
More Dell Technologies advisories
All Dell Technologies| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 7 | Dell OpenManage Server Administrator Managed Node: path traversal | Medium6.5 | 11.1.0.2+2 more |
| Aug 7 | Dell OpenManage Server Administrator Managed Node: improper authentication | High7.7 | OpenManage Server Administrator Managed Node (Patch) for...+2 more |
| Aug 6 | Dell Technologies Virtual Storage Integrator: information disclosure | Critical9.1 | 10.11.1.0 or later |
| Aug 6 | Dell Technologies RVTools: improper certificate validation | Medium6.8 | 4.8.1 or later |
| Aug 3 | Dell Technologies Display and Peripheral Manager: improper access control | High7.8 | 2.3.0.1005 |
| Aug 3 | Dell Technologies Display and Peripheral Manager: missing authentication | High7.8 | 2.3.0.1005 |