Description
Dell Client Platform BIOS contains an Authentication Bypass by Primary Weakness vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information Disclosure.
Published: 2026-07-03
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell Client Platform BIOS firmware contains a credential handling weakness (CWE‑305), allowing an attacker to bypass the primary authentication controls required for sensitive BIOS functions. If successful, the attacker can read protected data such as configuration settings, personal information, or other confidential information stored in the system. The vulnerability is only exploitable by an unauthenticated attacker who has physical access to the device, making it a local physical attack vector.

Affected Systems

Virtually all Dell client devices, including Latitude, Vostro, Alienware, Precision, OptiPlex, Pro, and many other laptop, ultrabook, all‑in‑one, and workstation models. All devices running BIOS firmware versions older than the latest update are vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% indicates a very low but non‑zero probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires physical proximity to the device; environments with weak physical security controls are therefore at higher risk. If access sensitive configuration and system data, potentially impacting confidentiality and trust in corporate assets.

Generated by OpenCVE AI on July 21, 2026 at 10:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest BIOS update available through Dell’s DSA 2026‑195.
  • Enable BIOS password protection and secure boot to add an extra layer of firmware access control.
  • Restrict physical access to affected workstations by using lock cabinets, controlled access rooms, and monitoring in sensitive areas.

Generated by OpenCVE AI on July 21, 2026 at 10:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title BIOS Authentication Bypass Leading to Information Disclosure

Wed, 15 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title BIOS Authentication Bypass Leading to Information Disclosure

Tue, 14 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title BIOS Authentication Bypass Leading to Information Disclosure

Mon, 13 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title BIOS Authentication Bypass Leading to Information Disclosure

Mon, 13 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title BIOS Authentication Bypass Leading to Information Disclosure in Dell Clients

Sat, 11 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title BIOS Authentication Bypass Leading to Information Disclosure in Dell Clients

Fri, 10 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title BIOS Authentication Bypass Leaks Information with Physical Access

Thu, 09 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title BIOS Authentication Bypass Leaks Information with Physical Access

Thu, 09 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title BIOS Authentication Bypass Leading to Information Disclosure

Wed, 08 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
Title BIOS Authentication Bypass Leading to Information Disclosure

Tue, 07 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Dell BIOS Authentication Bypass Allowing Physical Attackers to Read Sensitive Data

Mon, 06 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Dell BIOS Authentication Bypass Allowing Physical Attackers to Read Sensitive Data

Sun, 05 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in Dell BIOS Enabling Information Disclosure

Sun, 05 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in Dell BIOS Enabling Information Disclosure

Sun, 05 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title BIOS Authentication Bypass Enables Information Disclosure

Sat, 04 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title BIOS Authentication Bypass Enables Information Disclosure

Sat, 04 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title BIOS Authentication Bypass Enables Information Disclosure with Physical Attack

Fri, 03 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title BIOS Authentication Bypass Enables Information Disclosure with Physical Attack

Fri, 03 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Description Dell Client Platform BIOS contains an Authentication Bypass by Primary Weakness vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information Disclosure.
Weaknesses CWE-305
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-07-07T02:13:16.372Z

Reserved: 2026-04-01T17:04:27.475Z

Link: CVE-2026-35159

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T10:15:02Z

Weaknesses
  • CWE-305

    Authentication Bypass by Primary Weakness