# CVE-2026-32657

## Summary

- **CVE ID:** CVE-2026-32657
- **Severity:** HIGH
- **CVSS Score:** 7.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
- **CWE:** CWE-61
- **Published:** Aug 18, 2026
- **Last Modified:** Aug 19, 2026

## Description

Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell PowerMax Version 10.3.0, Dell Unity Version 5.4, Dell PowerFlex Manager Version 4.5.4, Dell PowerFlex Intelligent Catalog Versions 46.377.00 and 46.382.00 and Dell PowerFlex Rack version 4.5.4 and prior versions, contain(s) an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

## Affected Products

- Dell — AppSync (0)
- Dell — Metro Node (0)
- Dell — UCC Edge (0)
- Dell — VxRail (0)
- Dell — PowerMax (0)
- Dell — Unity (0)
- Dell — PowerFlex Manager (0)
- Dell — PowerFlex Intelligent Catalog (0)
- Dell — PowerFlex Rack (0)

## References

- [CNA](https://www.dell.com/support/kbdoc/en-us/000497857/dsa-2026-220-security-update-for-dell-product-vulnerability)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.13%
- **EPSS Percentile:** 2.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._