CVE-2026-35157

Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an improper neutralization of formula elements in a CSV File vulnerability in the UI. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:elastic_cloud_storage:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:objectscale:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-11 10:16

Updated : 2026-06-17 10:40


NVD link : CVE-2026-35157

Mitre link : CVE-2026-35157

CVE.ORG link : CVE-2026-35157


JSON object : View

Products Affected

dell

  • elastic_cloud_storage
  • objectscale
CWE
CWE-1236

Improper Neutralization of Formula Elements in a CSV File