CVE-2026-40636: Dell Elastic Cloud Storage
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains a use of hard-coded credentials vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to filesystem access for attacker.
Affected products
- Dell Elastic Cloud Storage: from 3.8.1.0, before 4.3.0.0 (fixed in 4.3.0.0)
- Dell Objectscale: before 4.3.0.0 (fixed in 4.3.0.0)
Published 2026-05-11. Last modified 2026-06-17.