Description

Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to the execution of malicious HTML or JavaScript code in a victim user's web browser in the context of the vulnerable web application. Exploitation may lead to information disclosure, session theft, or client-side request forgery.

INFO

Published Date :

2026-02-17T19:41:10.526Z

Last Modified :

2026-03-06T18:57:26.524Z

Source :

dell
AFFECTED PRODUCTS

The following products are affected by CVE-2026-26357 vulnerability.

Vendors Products
Dell
  • Unisphere For Powermax
  • Unisphere For Powermax Virtual Appliance

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact