T
Threats
Dell Virtual Storage Integrator Critical Vulnerabilities
Dell has published a critical security update for Virtual Storage Integrator for VMware vSphere Client. The update addresses an OS command injection vulnerability and a sensitive information disclosure vulnerability affecting versions prior to 10.11.1.0.
Both vulnerabilities can be exploited remotely without authentication or user interaction. Successful exploitation could allow an attacker to impersonate authenticated users, including administrators, or take full control of the underlying VSI system with root privileges.
Overview
Vendor: Dell Technologies
Product: Dell Virtual Storage Integrator for VMware vSphere Client
CVEs: CVE-2026-67261, CVE-2026-54489
Overall severity: Critical
Advisory date: 6 August 2026
Affected Versions
CVE-2026-67261
Affected: Dell Virtual Storage Integrator for VMware vSphere Client versions prior to 10.11.1.0
Fixed: Version 10.11.1.0 or later
CVE-2026-54489
Affected: Dell Virtual Storage Integrator for VMware vSphere Client versions prior to 10.11.1.0
Fixed: Version 10.11.1.0 or later
Dell has not identified any explicitly unaffected versions or configurations. Version 10.11.1.0 and later contain the remediation.
Vulnerability Breakdown
CVE-2026-67261 – OS Command Injection
Severity: Critical
CVSS: 9.8
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description: An OS command injection vulnerability in the IAPI component could allow a remote attacker to execute arbitrary operating system commands on the underlying host.
Impact: Successful exploitation could provide root-level command execution and lead to a complete takeover of the VSI deployment and underlying infrastructure.
Conditions: The attack can be performed remotely without authentication or user interaction. Dell rates attack complexity as low.
CVE-2026-54489 – Sensitive Information Disclosure
Severity: Critical
CVSS: 9.1
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Description: A sensitive information disclosure vulnerability could expose active session credentials to a remote attacker.
Impact: Successful exploitation could enable session hijacking and full impersonation of authenticated users, including administrators.
Conditions: The attack can be performed remotely without authentication or user interaction. Dell rates attack complexity as low.
Mitigation
Identify all deployments of Dell Virtual Storage Integrator for VMware vSphere Client.
Confirm the installed version on each deployment.
Upgrade every version earlier than 10.11.1.0 to version 10.11.1.0 or later at the earliest opportunity.
Follow Dell's release documentation when planning and completing the upgrade.
Dell has not published a separate workaround in the advisory. Upgrading to a remediated version is the required action.
Summary for IT Teams
Product: Dell Virtual Storage Integrator for VMware vSphere Client
Threat Level: Critical, CVSS up to 9.8
Action Required: Upgrade all affected deployments to version 10.11.1.0 or later immediately.
Potential Impact: Unauthenticated session hijacking, administrator impersonation, root-level command execution, and complete system compromise.

