Sceawere
Vulnerability Detail
CVE-2026-67261UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Dell VSI OS Command Injection
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 1d ago
- Vendor
- Dell
- Product
- Virtual Storage Integrator for VMware vSphere Client
- Attack Type
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying operating system with root privileges. Exploitation may lead to a complete system takeover by an attacker. This vulnerability is considered critical as it allows an unauthenticated remote attacker to achieve arbitrary code execution as root, potentially compromising the entire VSI deployment and underlying infrastructure. Dell recommends customers to upgrade at the earliest opportunity.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-08-06T15:17:24.430Z",
"pubdate": "2026-08-06T15:17:24.430Z",
"executiveSummary": "Dell Virtual Storage Integrator for VMware vSphere Client versions prior to 10.11.1.0 contain a critical OS Command Injection vulnerability located within the IAPI component. This security flaw allows a remote, unauthenticated attacker to execute arbitrary OS commands directly on the underlying operating system.\nThe vulnerability poses an extreme risk to organizational infrastructure, as successful exploitation grants the attacker root privileges, potentially leading to a complete system takeover of the affected VSI deployment.\nGiven that the attack vector requires no prior authentication or user interaction, threat actors can leverage network exposure to achieve arbitrary code execution remotely.\nDell has identified this vulnerability as critical and strongly recommends that administrators upgrade affected installations to version 10.11.1.0 or later at the earliest opportunity to mitigate the associated risks.",
"technicalDetails": "The vulnerability is classified as an OS Command Injection flaw residing in the IAPI component of Dell Virtual Storage Integrator for VMware vSphere Client.\nThe root cause stems from improper sanitization and validation of input supplied by users, which is subsequently passed to the underlying operating system shell for execution.\nThe affected software versions include all deployments of Dell Virtual Storage Integrator for VMware vSphere Client prior to version 10.11.1.0.\nThe attack vector is network-exposed, allowing a remote attacker to interact directly with the vulnerable IAPI component without requiring any prior authentication or valid session credentials.\nDuring the attack flow, an unauthenticated attacker transmits a crafted HTTP request or payload containing malicious OS commands to the IAPI endpoint.\nBecause input filtering and command escaping are absent or insufficient, the vulnerable component passes the malicious payload directly to the underlying system shell.\nThe operating system processes and executes the injected commands, inheriting the security context of the application process.\nDue to the overly permissive execution context, the injected commands are executed with root privileges on the underlying operating system.\nPost-exploitation impact includes full system compromise, unauthorized data access, modification or deletion of sensitive system configurations, installation of persistent backdoors, and potential pivot opportunities into the broader VMware vSphere infrastructure managed by the integration."
}