Description
Dell Client Platform BIOS contains an Authentication Bypass by Primary Weakness vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information Disclosure.
Published: 2026-07-03
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell Client Platform BIOS firmware contains a credential handling weakness (CWE‑305) that allows an unauthenticated attacker with physical access to bypass primary authentication controls for BIOS functions. If the bypass succeeds, the attacker may read sensitive data stored in firmware or other system configuration areas, leading to confidential information disclosure. The flaw does not grant code execution; its primary impact is confidentiality compromise rather than integrity or availability disruption.

Affected Systems

Virtually all Dell client devices listed in the CNA products—including Latitude, Vostro, Alienware, Precision, OptiPlex, Pro, and numerous Ultrabook, All‑in‑One, and workstation models—are affected. The CVE does not specify firmware versions, so any device running a BIOS firmware containing the identified weakness is vulnerable, regardless of make or model within the Dell client portfolio.

Risk and Exploitability

The CVSS score of 5.3 marks moderate severity, while the EPSS score of less than 1% indicates a very low probability of exploitation in the general population. The flaw is exploitable only by an attacker who can physically access the device; therefore, environments with weak physical security controls present higher risk. Even though the vulnerability is not listed in CISA’s KEV catalog, it remains relevant for organizations that rely on strong physical safeguards to protect firmware integrity.

Generated by OpenCVE AI on August 3, 2026 at 05:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest BIOS update available through Dell DSA 2026‑195 to eliminate the firmware weakness.
  • Configure a strong BIOS administrator password and enable Secure Boot to add an additional layer of firmware access control.
  • Enforce physical security controls such as lock‑mounted chassis, restricted access rooms, and monitoring to prevent unauthorized physical access to vulnerable devices.

Generated by OpenCVE AI on August 3, 2026 at 05:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title BIOS Authentication Bypass Enables Information Disclosure on Dell Devices

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title BIOS Authentication Bypass Enables Information Disclosure on Dell Devices

Tue, 21 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title BIOS Authentication Bypass Leading to Information Disclosure

Wed, 15 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title BIOS Authentication Bypass Leading to Information Disclosure

Tue, 14 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title BIOS Authentication Bypass Leading to Information Disclosure

Mon, 13 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title BIOS Authentication Bypass Leading to Information Disclosure

Mon, 13 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title BIOS Authentication Bypass Leading to Information Disclosure in Dell Clients

Sat, 11 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title BIOS Authentication Bypass Leading to Information Disclosure in Dell Clients

Fri, 10 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title BIOS Authentication Bypass Leaks Information with Physical Access

Thu, 09 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title BIOS Authentication Bypass Leaks Information with Physical Access

Thu, 09 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title BIOS Authentication Bypass Leading to Information Disclosure

Wed, 08 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
Title BIOS Authentication Bypass Leading to Information Disclosure

Tue, 07 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Dell BIOS Authentication Bypass Allowing Physical Attackers to Read Sensitive Data

Mon, 06 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Dell BIOS Authentication Bypass Allowing Physical Attackers to Read Sensitive Data

Sun, 05 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in Dell BIOS Enabling Information Disclosure

Sun, 05 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in Dell BIOS Enabling Information Disclosure

Sun, 05 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title BIOS Authentication Bypass Enables Information Disclosure

Sat, 04 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title BIOS Authentication Bypass Enables Information Disclosure

Sat, 04 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title BIOS Authentication Bypass Enables Information Disclosure with Physical Attack

Fri, 03 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title BIOS Authentication Bypass Enables Information Disclosure with Physical Attack

Fri, 03 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Description Dell Client Platform BIOS contains an Authentication Bypass by Primary Weakness vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information Disclosure.
Weaknesses CWE-305
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-07-07T02:13:16.372Z

Reserved: 2026-04-01T17:04:27.475Z

Link: CVE-2026-35159

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-03T09:16:36.937

Modified: 2026-07-07T02:16:29.577

Link: CVE-2026-35159

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T05:30:17Z

Weaknesses
  • CWE-305

    Authentication Bypass by Primary Weakness