cbcvebase.
CVE-2026-22275
published 2026-01-23

CVE-2026-22275: Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains an Inclusion of Sensitive Information in Source Code…

PriorityP418medium4.4CVSS 3.1
AVLACLPRLUINSUCLILAN
EPSS
0.13%
2.8th percentile
Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains an Inclusion of Sensitive Information in Source Code vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.

Affected

3 ranges
VendorProductVersion rangeFixed in
dellelastic_cloud_storage>= 3.8.1.0 < 4.2.0.04.2.0.0
dellobjectscale< 4.2.0.04.2.0.0
dellobjectscale>= N/A < 4.2.0.04.2.0.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.