Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4358 articles · 196341 vulns · 36/41 feeds (7d)
← Back to list
7.3
CVE-2026-56685PATCHED
dell · objectscale

CVE-2026-56685: Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Com

Description

Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution.

Affected Products

VendorProductVersions
dellobjectscale0

References

  • https://www.dell.com/support/kbdoc/en-us/000500724/dsa-2026-328-security-update-for-dell-objectscale-multiple-proprietary-code-vulnerabilities(vendor-advisory)

Related News (2 articles)

Tier D
Heise Security2d ago
Dell ObjectScale: Höhere Nutzerrechte erschleichbar
→ No new info (linked only)
Tier C
VulDB6d ago
CVE-2026-56685 | Dell ObjectScale 3.8.1.7/4.1.0.3/4.2.0.0 os command injection
→ No new info (linked only)
CVSS 3.17.3 HIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
4.3.0.1 or later
CWECWE-78
PublishedAug 17, 2026
Last enriched6d ago
Trending Score30
Source articles2
Independent2
Info Completeness5/14
Missing: vendor, product, versions, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-67271
CVE-2026-67271: Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the SMB/CIFS. An unauthenticated attacker with r
Trending: 24
MEDIUMCVE-2026-59911
CVE-2026-59911: Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Insertion of Sensitive Information into Log File vulnerabilit
Trending: 23
HIGHCVE-2026-54794
CVE-2026-54794: Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side Request Forgery (SSRF) vulnerability. An una
Trending: 21
HIGHCVE-2026-58565
CVE-2026-58565: Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged atta
Trending: 18
HIGHCVE-2026-23501
CVE-2026-23501: Dell RecoverPoint for VMs, versions 6.0.3 and 6.0.3.1, contains an Improper Neutralization of Special Elements used in a
Trending: 18

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 17, 2026
Discovered by ZDM
Aug 17, 2026
Patch Available
Aug 17, 2026