Description
UPS Multi-UPS Management Console (MUMC) version 01.06.0001 (A03) contains an Unquoted Search Path or Element (CWE-428) vulnerability, which allows a user with write access to a directory on the system drive to execute arbitrary code with SYSTEM privileges.
Published: 2026-03-05
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary Code Execution with SYSTEM privileges
Action: Immediate Patch
AI Analysis

Impact

The Dell UPS Multi‑UPS Management Console (MUMC) version 01.06.0001 (A03) implements an unquoted search path mechanism that is exploited by an attacker to direct the system to execute a malicious file that the attacker has placed in a writable directory on the system drive. This flaw falls under CWE‑428 and allows an attacker to run arbitrary code with SYSTEM privileges, thereby compromising confidentiality, integrity, and availability of the UPS system as well as any other services running on the same machine.

Affected Systems

Systems running Dell Inc.’s UPS Multi‑UPS Management Console, specifically version 01.06.0001 (A03), are affected. No other Dell UPS software versions are listed as impacted in the available data. The vulnerability is tied to the console’s handling of unquoted paths during executable resolution on the system drive.

Risk and Exploitability

The CVSS score of 8.4 marks this flaw as high severity. The EPSS score being less than 1 % indicates a very low estimated exploitation probability at this time, and the vulnerability is not currently tracked in CISA’s KEV catalog. However, the attack requires a local user with write access to a system‑drive directory, so if such privileges are available, the exploitation is straightforward and the impact is immediate. The high privilege escalation potential warrants urgent attention, even though the likelihood of deployment in the wild remains low.

Generated by OpenCVE AI on April 16, 2026 at 12:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Dell’s latest update for the UPS Multi‑UPS Management Console (driverid 038h3) to replace the vulnerable executable with a fixed version.
  • Restrict write permissions on any directories located on the system drive so that only trusted administrators can add or modify files, preventing the placement of malicious binaries in those paths.
  • If a patch is not available immediately, move the console’s executable files to a directory that is not part of an unquoted search path or modify the environment so that the system’s search path includes only quoted entries, thereby blocking unquoted-path execution.

Generated by OpenCVE AI on April 16, 2026 at 12:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 16 Apr 2026 13:15:00 +0000

Type Values Removed Values Added
Title Unquoted Search Path in Dell UPS Multi‑UPS Management Console Enables Arbitrary Code Execution

Mon, 09 Mar 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell ups Multi-ups Management Console
CPEs cpe:2.3:a:dell:ups_multi-ups_management_console:01.06.0001_\(a03\):*:*:*:*:*:*:*
Vendors & Products Dell
Dell ups Multi-ups Management Console

Fri, 06 Mar 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell Inc.
Dell Inc. ups Multi-ups Management Console (mumc)
Vendors & Products Dell Inc.
Dell Inc. ups Multi-ups Management Console (mumc)

Thu, 05 Mar 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 05 Mar 2026 03:15:00 +0000

Type Values Removed Values Added
Description UPS Multi-UPS Management Console (MUMC) version 01.06.0001 (A03) contains an Unquoted Search Path or Element (CWE-428) vulnerability, which allows a user with write access to a directory on the system drive to execute arbitrary code with SYSTEM privileges.
Weaknesses CWE-428
References
Metrics cvssV3_0

{'score': 6.7, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Dell Ups Multi-ups Management Console
Dell Inc. Ups Multi-ups Management Console (mumc)
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-03-05T15:41:51.417Z

Reserved: 2026-02-10T05:52:34.659Z

Link: CVE-2026-26033

cve-icon Vulnrichment

Updated: 2026-03-05T15:32:43.611Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-05T03:15:54.333

Modified: 2026-03-09T18:43:50.357

Link: CVE-2026-26033

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T13:00:11Z

Weaknesses
  • CWE-428

    Unquoted Search Path or Element