Dell ObjectScale Critical Deserialization Flaw (CVE-2026-70416, CVSS 10.0) Enables Unauthenticated RCE

Dell ObjectScale Critical Deserialization Flaw (TL-2026-2475) is a critical-severity software vulnerability scored CVSS 10, first published 2026-09-13. It has no confirmed attribution, affects Dell Technologies ObjectScale, references 5 CVEs (CVE-2026-70416, CVE-2025-43936, CVE-2026-26947), maps to 7 MITRE ATT&CK techniques (T1190, T1485, T1489), and is covered by 9 detection rules and 12 indicators of compromise.

Key facts for TL-2026-2475

Threat ID
TL-2026-2475
Severity
CRITICAL
CVSS
10
Status
ACTIVE
Category
VULNERABILITY
First published
2026-09-13
Last reviewed
2026-09-13
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, research and education, enterprise it, cloud service providers, managed service providers, backup and disaster recovery
Target regions
Global
Detection rules
9
Indicators of compromise
12

Dell's DSA-2026-393 (published 2026-09-10) discloses five ObjectScale/ECS vulnerabilities led by CVE-2026-70416, a CVSS 10.0 untrusted-data deserialization flaw in ObjectScale < 4.4.0.0 that lets an unauthenticated remote attacker execute code. A bundled improper-authentication flaw (CVE-2025-43936, CVSS 8.1) also grants unauthenticated remote access at high attack complexity, alongside three lower-severity local/administrative issues. Dell shipped fixed version 4.4.0.0 (with a direct 4.2.0.1 upgrade path); no in-the-wild exploitation or public PoC has been reported as of 2026-09-13.

How Dell ObjectScale Critical Deserialization Flaw works

On 2026-09-10 Dell Technologies published security advisory DSA-2026-393, covering five vulnerabilities in ObjectScale (and, for several of the flaws, the related Elastic Cloud Storage/ECS product line). The headline issue, CVE-2026-70416, is a CVSS 10.0 untrusted-data deserialization vulnerability (CWE-502) affecting all ObjectScale versions prior to 4.4.0.0. Because the flaw requires no authentication and no user interaction, a remote attacker can send malicious serialized data to trigger the vulnerable deserialization path and achieve arbitrary code execution on the target system. Dell's own advisory language states that successful exploitation could give the attacker control over the ObjectScale environment, enabling them to access data, alter configurations, disrupt storage operations, deploy malicious payloads, or establish persistence in the affected infrastructure -- effectively full compromise of the storage platform.

The same advisory bundles a second high-severity, unauthenticated issue, CVE-2025-43936 (CVSS 8.1), an improper-authentication flaw (CWE-287) that also permits unauthorized remote access to ObjectScale (and ECS 3.8.1.0-3.8.1.7), though it requires high attack complexity to exploit versus the trivial CVE-2026-70416. Three additional, lower-severity issues round out DSA-2026-393: CVE-2026-26947 (CVSS 6.7, improper privilege management, CWE-269, requires a high-privileged local attacker, affects ECS 3.8.1.0-3.8.1.7 and ObjectScale < 4.4.0.0, impacting confidentiality, integrity, and availability once escalated), CVE-2026-76104 (CVSS 5.5, incorrect permission assignment for a critical resource, CWE-732, described in independent reporting as an operating-system-level permission flaw rather than a purely application-layer bug, exploitable by a remote high-privileged administrator to cause denial-of-service conditions by altering that resource's permissions), and CVE-2025-36591 (CVSS 4.4, use of a broken/weak cryptographic algorithm, CWE-327, requiring local access and high privileges, leading to sensitive information exposure).

DSA-2026-393 additionally bundles fixes for third-party components shipped inside ObjectScale -- Apache Log4j (CVE-2026-34477, CVE-2026-34478, CVE-2026-34480), liblzma/XZ Utils (CVE-2026-34743), and the underlying Linux kernel (CVE-2026-31694, CVE-2026-43499) -- reflecting that a full remediation also pulls in upstream component patches, not just Dell proprietary code changes. No exploitation mechanism, attack vector, or CVSS-vector detail beyond the CVE IDs themselves was found in the reviewed reporting for these six bundled third-party CVEs, so they are tracked here as remediation-relevant context rather than independently analyzed vulnerabilities.

Dell credits security researcher WinD39 (Huynh Dinh Vu) for reporting CVE-2026-70416 through Dell's coordinated vulnerability disclosure program. No public proof-of-concept and no confirmed in-the-wild exploitation have been reported for any of the five CVEs as of this writing. As of 2026-09-13, direct verification against the NVD CVE 2.0 REST API (services.nvd.nist.gov) returned zero populated records for CVE-2026-70416, CVE-2025-43936, CVE-2026-26947, CVE-2026-76104, and CVE-2025-36591, and the CVE.org record pages for these IDs likewise had not yet rendered scored/structured content -- indicating the federal vulnerability databases have not finished ingesting and scoring this three-day-old disclosure, so Dell's own advisory and independent security-media reporting remain the primary available sources. Dell's remediation guidance is to upgrade to ObjectScale 4.4.0.0 or later (customers on supported release trains may instead upgrade directly to 4.2.0.1), and, pending patching, to restrict administrative and storage-management interfaces to trusted networks, monitor for abnormal authentication activity, and investigate unexpected configuration or permission changes.

ObjectScale and ECS are Dell's enterprise S3-compatible object-storage platforms, marketed for cloud-native, AI/analytics, big-data, backup/archive, and data-lake workloads in VMware and Red Hat OpenShift environments, with a customer base that includes enterprise, government, and research-institution deployments -- meaning a compromised, internet- or internal-network-exposed management interface could expose, corrupt, or destroy large volumes of an organization's primary data-lake or backup storage.

MITRE ATT&CK techniques used in TL-2026-2475

Initial Access

T1190 Exploit Public-Facing Application

Impact

T1485 Data Destruction; T1489 Service Stop; T1565 Data Manipulation

Persistence

T1505 Server Software Component

Collection

T1530 Data from Cloud Storage

Credential Access

T1552 Unsecured Credentials

Affected products and versions in Dell ObjectScale Critical Deserialization Flaw

  • Dell Technologies — ObjectScale
    Vulnerable versions: < 4.4.0.0
    Fixed in: 4.4.0.0; 4.2.0.1 (direct upgrade path for supported release trains)
  • Dell Technologies — ECS (Elastic Cloud Storage)
    Vulnerable versions: 3.8.1.0-3.8.1.7
    Fixed in: Per DSA-2026-393 upgrade guidance; reference the advisory via an Operating Environment Upgrade service request

Remediation for Dell ObjectScale Critical Deserialization Flaw

Patches

  • Dell ObjectScale 4.4.0.0 (primary fix for all five CVEs)
  • Dell ObjectScale 4.2.0.1 (alternate direct-upgrade path for supported release trains)

Immediate actions

  • Upgrade Dell ObjectScale to version 4.4.0.0 or later
  • Where an immediate upgrade to 4.4.0.0 is not possible on a supported release train, upgrade directly to 4.2.0.1 per DSA-2026-393
  • Restrict administrative and storage-management interfaces to trusted, segmented networks -- do not expose them to the internet or broad internal VLANs
  • Review current exposure of ObjectScale and ECS management endpoints and close unnecessary network access

Workarounds

  • No vendor-published functional workaround beyond network segmentation and access restriction to the management interface; upgrading is the only complete remediation

Longer-term hardening

  • Monitor for abnormal authentication activity against ObjectScale/ECS management interfaces
  • Investigate unexpected configuration or permission changes on ObjectScale/ECS systems
  • Track and apply patches for the bundled third-party components (Apache Log4j, liblzma, Linux kernel) shipped inside the same advisory
  • Establish a recurring patch-management cadence for Dell storage software given the frequency of prior DSAs against this product line (DSA-2026-019, DSA-2026-047, DSA-2026-143, DSA-2026-328, DSA-2026-393)

CVEs associated with Dell ObjectScale Critical Deserialization Flaw

CVE-2026-70416, CVE-2025-43936, CVE-2026-26947, CVE-2026-76104, CVE-2025-36591

Weaknesses (CWE) in Dell ObjectScale Critical Deserialization Flaw

CWE-502, CWE-287, CWE-269, CWE-732, CWE-327

Timeline of Dell ObjectScale Critical Deserialization Flaw

  • Daily CyberSecurity (securityonline.info) publishes an independent technical write-up corroborating CVE-2026-70416's CVSS 10.0 score and unauthenticated deserialization root cause.
  • Cyber Security News publishes the first public summary of DSA-2026-393 and its five CVEs.
  • Dell makes fixed ObjectScale version 4.4.0.0 available, with a direct upgrade path to 4.2.0.1 for supported release trains.
  • Dell credits security researcher WinD39 (Huynh Dinh Vu) for responsibly reporting CVE-2026-70416 through its coordinated disclosure program.
  • Dell Technologies publishes security advisory DSA-2026-393, disclosing five ObjectScale/ECS vulnerabilities led by CVE-2026-70416 (CVSS 10.0).
  • Direct query of the NVD CVE 2.0 REST API confirms zero populated records for all five DSA-2026-393 CVE IDs three days post-disclosure, indicating federal vulnerability-database enrichment (CVSS/CWE re-scoring, reference tagging) is still pending for this advisory.
  • Threadlinqs Intelligence Platform ingests the disclosure via RSS hunt and opens tracking as TL-2026-2475; no in-the-wild exploitation or public PoC identified as of this date.

Sources cited for Dell ObjectScale Critical Deserialization Flaw

More in vulnerability

Detection coverage for TL-2026-2475

As of 2026-09-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2475 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats