Cyber Posture

CVE-2026-26360

High

Published: 19 February 2026

Published
19 February 2026
Modified
20 February 2026
KEV Added
Patch
CVSS Score 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
EPSS Score 0.0008 22.4th percentile
Risk Priority 16 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2026-26360 is a high-severity External Control of File Name or Path (CWE-73) vulnerability in Dell Unisphere For Powermax. Its CVSS base score is 8.1 (High).

Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 22.4th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified are NIST 800-53 SI-10 (Information Input Validation) and SI-2 (Flaw Remediation).

Threat & Defense at a Glance

What attackers do: exploitation maps to Exploit Public-Facing Application (T1190) and 1 other technique. What defenders deploy: see the NIST 800-53 controls recommended below.
Threat & Defense Details

Mitigating Controls (NIST 800-53 r5)AI

prevent

Directly mitigates the vulnerability by identifying, reporting, and applying the vendor-released security patch for CVE-2026-26360 as detailed in Dell's advisory.

prevent

Prevents exploitation of the External Control of File Name or Path vulnerability by validating and sanitizing remote inputs to block arbitrary file path manipulation and traversal attacks.

prevent

Enforces approved access authorizations to limit low-privileged remote attackers from deleting arbitrary files even if path manipulation partially succeeds.

MITRE ATT&CK Enterprise TechniquesAI

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
T1485 Data Destruction Impact
Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources.
Why these techniques?

Remote network-accessible management application vulnerability (CWE-73) directly enables exploitation via T1190 to achieve arbitrary file deletion, mapping to T1485 for disruption of integrity/availability on critical systems.

Confidence: HIGH · MITRE ATT&CK Enterprise v18.1

NVD Description

Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability to delete arbitrary files.

Deeper analysisAI

CVE-2026-26360 is an External Control of File Name or Path vulnerability (CWE-73) affecting Dell Unisphere for PowerMax version 10.2. This flaw allows unauthorized manipulation of file paths, earning a CVSS v3.1 base score of 8.1 (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H), indicating high severity due to its potential for integrity and availability impacts over the network with low complexity and low privileges required.

A low-privileged attacker with remote access can exploit this vulnerability to delete arbitrary files on the affected system. The attack requires no user interaction and maintains an unchanged scope, enabling disruption of critical storage management operations in PowerMax environments without compromising confidentiality.

Dell's security advisory DSA-2026-102, detailed at https://www.dell.com/support/kbdoc/en-us/000429268/dsa-2026-102-dell-unisphere-for-powermax-and-powermax-eem-security-update-for-multiple-vulnerabilities, addresses this and other vulnerabilities in Unisphere for PowerMax and PowerMax EEM with a security update. Practitioners should apply the patch to mitigate exploitation risks.

Details

CWE(s)

Affected Products

dell
unisphere for powermax
≤ 10.3.0.1 · ≤ 10.3.0.1

CVEs Like This One

CVE-2026-26359Same product: Dell Unisphere For Powermax
CVE-2026-26358Same product: Dell Unisphere For Powermax
CVE-2026-26362Same product: Dell Unisphere For Powermax
CVE-2025-36589Same product: Dell Unisphere For Powermax
CVE-2025-36588Same product: Dell Unisphere For Powermax
CVE-2025-24383Same vendor: Dell
CVE-2026-26944Same vendor: Dell
CVE-2026-22266Same vendor: Dell
CVE-2025-26336Same vendor: Dell
CVE-2025-43995Same vendor: Dell

References