CVE-2025-26478: Dell Elastic Cloud Storage
Medium severity, CVSS 6.5. EPSS: 0.1% chance of exploitation in the next 30 days.
Dell ECS version 3.8.1.4 and prior contain an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure.
Affected products
- Dell Elastic Cloud Storage: up to and including 3.8.1.4
- Dell Objectscale: before 4.0.0.0 (fixed in 4.0.0.0)
Published 2025-04-17. Last modified 2026-06-17.