Description
Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell PowerMax Version 10.3.0, Dell Unity Version 5.4, Dell PowerFlex Manager Version 4.5.4, Dell PowerFlex Intelligent Catalog Versions 46.377.00 and 46.382.00 and Dell PowerFlex Rack version 4.5.4 and prior versions, contain(s) an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Published: 2026-08-18
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw lies in the way Dell AppSync, Metro Node, PowerMax, UCC Edge, VxRail, Unity, and PowerFlex components resolve UNIX symbolic links. If a local user can create or manipulate a symlink that points to a privileged system file and trigger the application to follow it, the attacker can write or overwrite critical configuration or system files, which enables elevation of privileges, consistent with CWE‑61 Path Traversal. The CVE description explicitly states that a low‑privileged local attacker could exploit this to gain higher privileges.

Affected Systems

Affected products include Dell AppSync 4.6.0.0, Dell Metro Node 8.0.0, Dell UCC Edge 3.0.1, Dell VxRail 8.0.322, Dell PowerMax 10.3.0, Dell Unity 5.4, Dell PowerFlex Manager 4.5.4, Dell PowerFlex Intelligent Catalog 46.377.00 and 46.382.00, and Dell PowerFlex Rack 4.5.4 and prior versions. All listed versions run on Linux‐based systems that handle symbolic link resolution as described.

Risk and Exploitability

The CVSS score of 7.3 indicates moderate to high severity. The EPSS score is not available, so the current exploitation probability is uncertain; however, the vulnerability is listed in the CISA KEV catalog as not present, suggesting no confirmed exploits at this time. The likely attack vector requires local access with low privileges, making the risk contingent on the attacker’s ability to gain a foothold on the host. Abuse of the symlink following behavior can allow the attacker to modify crucial files and thereby elevate privileges, posing a significant threat to confidentiality, integrity, and availability of the affected systems.

Generated by OpenCVE AI on August 18, 2026 at 19:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Dell’s latest security update for the affected products that patches the symbolic‑link following issue.
  • Restrict local user privilege and enforce least‑privilege principles to prevent creation or modification of symbolic links in application directories.
  • Disable or restrict the symbolic link following capability in the affected applications or the filesystem, and enforce strict file permissions.
  • Monitor file‑system changes and privilege escalation attempts, and conduct regular integrity checks for critical system files.

Generated by OpenCVE AI on August 18, 2026 at 19:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Title Symbolic Link Following Vulnerability Enables Local Privilege Escalation in Dell Products

Tue, 18 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell PowerMax Version 10.3.0, Dell Unity Version 5.4, Dell PowerFlex Manager Version 4.5.4, Dell PowerFlex Intelligent Catalog Versions 46.377.00 and 46.382.00 and Dell PowerFlex Rack version 4.5.4 and prior versions, contain(s) an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Weaknesses CWE-61
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-19T03:56:07.666Z

Reserved: 2026-03-12T17:04:27.868Z

Link: CVE-2026-32657

cve-icon Vulnrichment

Updated: 2026-08-18T18:42:41.142Z

cve-icon NVD

Status : Received

Published: 2026-08-18T18:17:28.573

Modified: 2026-08-19T04:16:58.420

Link: CVE-2026-32657

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T20:00:04Z

Weaknesses
  • CWE-61

    UNIX Symbolic Link (Symlink) Following