CVE-2026-35157: Dell Elastic Cloud Storage

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an improper neutralization of formula elements in a CSV File vulnerability in the UI. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.

Affected products

  • Dell Elastic Cloud Storage: from 3.8.1.0, before 4.3.0.0 (fixed in 4.3.0.0)
  • Dell Objectscale: before 4.3.0.0 (fixed in 4.3.0.0)

Published 2026-05-11. Last modified 2026-06-17.