← All Advisories

Dell Virtual Storage Integrator for VMware vSphere Client Exposes Sensitive Information to Unauthenticated Remote Attackers, Enabling Information Disclosure and Session Hijacking

Last refreshed2026-09-28

Status: UPDATED  |  Advisory ID: CVE-2026-54489

Key Details

CVECVE-2026-54489
CVSS Score / Version9.1 (Critical) / CVSS v3.1
Updated2026-08-07
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is none.
Affected productsdell virtual_storage_integrator
Classified asCWE-200 (Exposure of Sensitive Information to an Unauthorized Actor)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
dellvirtual_storage_integrator
SubsystemsGeneral OT
SectorsMultiple

What to Know

Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session hijacking. This vulnerability is considered critical as it allows an unauthenticated attacker to obtain active session credentials and fully impersonate authenticated users, including administrators. Dell recommends customers to upgrade at the earliest opportunity. (NVD)

What to Do

Monitor dell's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-54489
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-54489
Vendor advisoryhttps://www.dell.com/support/kbdoc/en-us/000496035/dsa-2026-335-security-update-for-dell-virtual-storage-integrator-for-vmware-vsphere-client-multiple-vulnerabilities