CVE-2026-22273 Details
Description
Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains an Use of Default Credentials vulnerability in the OS. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
A vulnerability allowing the use of default credentials has been identified in Dell ECS versions 3.8.1.0 through 3.8.1.7, and in Dell ObjectScale versions prior to 4.2.0.0. This vulnerability could be exploited by a low-privileged attacker with remote access, potentially leading to unauthorized elevation of privileges.
Customers using Dell ECS or ObjectScale can change default credentials by following the password change procedure outlined in the Dell ObjectScale 4.2.0.0 Security Configuration Guide. Those on ECS should upgrade to version 4.2.0.0 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.dell.com/support/kbdoc/en-us/000415880/dsa-2026-047-security-update-for-dell-ecs-and-objectscale-multiple-vulnerabilities | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1392 | Use of Default Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| dell elastic cloud storage | >= 3.8.1.0, < 4.2.0.0 |
CPE
Remediation
| |
| dell objectscale | < 4.2.0.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 18, 2026 | Initial Analysis | [email protected] |
| Jan 23, 2026 | New CVE Received | [email protected] |