Dell Technologies has issued a security advisory detailing significant vulnerabilities in its ObjectScale and Elastic Cloud Storage (ECS) systems. These vulnerabilities, if exploited, could allow unauthorized remote code execution, posing a severe risk to enterprise environments. The advisory, identified as DSA-2026-393, highlights several flaws, with the most critical being CVE-2026-70416. This particular flaw is an untrusted data deserialization vulnerability in ObjectScale versions earlier than 4.4.0.0, carrying a maximum CVSS score of 10.0. Unauthenticated attackers could leverage this flaw to execute arbitrary code, thereby gaining control over the ObjectScale environment. Such control could lead to unauthorized data access, configuration changes, disruption of storage operations, and potential deployment of malicious payloads.
Organizations relying on ObjectScale for large-scale object storage are particularly at risk, especially those storing backups, application data, archives, or cloud-native workloads. The advisory also covers CVE-2025-43936, an improper authentication vulnerability with a CVSS score of 8.1, which affects ObjectScale versions prior to 4.4.0.0. Although it is complex to exploit, it does not require credentials or user interaction, underscoring the urgency of network exposure limitations during the update process.
Additional vulnerabilities include CVE-2026-26947, an improper privilege management flaw with a score of 6.7, and CVE-2025-36591, a cryptographic algorithm issue rated 4.4, both impacting ECS and ObjectScale. Furthermore, CVE-2026-76104, related to incorrect permission assignment, could lead to denial-of-service conditions. The advisory also notes vulnerabilities in third-party components such as Apache Log4j and the Linux kernel.
To mitigate these risks, Dell advises upgrading affected systems to ObjectScale version 4.4.0.0 or newer. Customers can also update to version 4.2.0.1 if applicable. Dell recommends following their Secure Service-Level Communication guidance to mitigate CVE-2025-43936 until updates are applied. Security teams should restrict access to administrative interfaces, monitor for abnormal activity, and review service exposures. Dell acknowledged security researcher WinD39, also known as Huynh Dinh Vu, for reporting CVE-2026-70416.

