Description
Dell Alienware Command Center (AWCC), versions prior to 6.13.8.0, contain a Least Privilege Violation vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Published: 2026-04-27
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Elevation of Privileges
Action: Patch
AI Analysis

Impact

The vulnerability is a Least Privilege Violation that allows an attacker with local, low-level access to raise their privileges on a system running Dell Alienware Command Center. According to the CVE description, exploitation could lead to an attacker gaining higher privileges than originally granted, potentially enabling further unauthorized actions such as modifying system settings or installing malicious software. The weakness aligns with CWE-272, which indicates a flaw in enforcing correct privilege levels for authorized actions.

Affected Systems

Dell Alienware Command Center (AWCC) versions prior to 6.13.8.0 are affected. The vulnerability applies to all installations of AWCC that have not been updated beyond this version threshold, regardless of the operating system or deployment configuration.

Risk and Exploitability

The CVSS score of 5.3 reflects a moderate severity assessment. The EPSS score is not available, so the likelihood of exploitation in the wild is unknown. The vulnerability is not listed in the CISA KEV catalog, indicating it has not been identified as a currently exploited vulnerability. Exploitation requires local, low-privilege access, suggesting that it is primarily a threat to users who have physical or local network access to the target machine. The attacker would need to execute privileged operations through the AWCC application in order to elevate their rights.

Generated by OpenCVE AI on April 28, 2026 at 19:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Dell Alienware Command Center to version 6.13.8.0 or newer following Dell's security update guidelines.
  • Configure user accounts running AWCC with the minimal privileges necessary, adhering to the principle of least privilege.
  • Enable and monitor audit logging for AWCC-related actions, ensuring that local administrators receive alerts for potential privilege escalation attempts.

Generated by OpenCVE AI on April 28, 2026 at 19:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:dell:alienware_command_center:*:*:*:*:*:*:*:*

Tue, 28 Apr 2026 20:00:00 +0000

Type Values Removed Values Added
Title Least Privilege Violation in Dell Alienware Command Center Leading to Local Privilege Escalation

Tue, 28 Apr 2026 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Apr 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell alienware Command Center
Vendors & Products Dell
Dell alienware Command Center

Mon, 27 Apr 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Apr 2026 18:45:00 +0000

Type Values Removed Values Added
Description Dell Alienware Command Center (AWCC), versions prior to 6.13.8.0, contain a Least Privilege Violation vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Weaknesses CWE-272
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L'}


Subscriptions

Dell Alienware Command Center
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-04-28T12:48:20.397Z

Reserved: 2026-03-12T17:04:27.868Z

Link: CVE-2026-32655

cve-icon Vulnrichment

Updated: 2026-04-27T19:42:53.019Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-27T19:16:47.387

Modified: 2026-04-28T20:13:23.880

Link: CVE-2026-32655

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T19:45:07Z

Weaknesses