Description
Dell Command | Monitor (DCM), versions prior to 10.13.2, contain an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Published: 2026-09-21
Score: 8.4 High
EPSS: n/a
KEV: No
Impact: Elevation of Privileges
Action: Apply Patch
AI Analysis

Impact

Dell Command | Monitor (DCM) versions prior to 10.13.2 contain an Incorrect Permission Assignment for Critical Resource vulnerability that allows a local user with low privileges to gain elevated privileges by manipulating a protected resource. This flaw can be used to bypass the intended access controls on the system, giving the attacker full control over the affected device.

Affected Systems

The vulnerability is present in Dell Command | Monitor (DCM) software prior to version 10.13.2, specifically in the Dell:Command | Monitor product line.

Risk and Exploitability

The CVSS score of 8.4 signals a high‑severity issue, but the EPSS score is not available and the vulnerability is not listed in CISA KEV, indicating that widespread exploitation has not yet been observed. Because the attack requires local access, the risk is confined to environments where attackers can physically or otherwise gain local user rights. Nonetheless, the potential for privilege escalation makes timely patching critical.

Generated by OpenCVE AI on September 21, 2026 at 20:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Dell Command | Monitor to version 10.13.2 or later using Dell’s security update.
  • Ensure the updated installation has the corrected permission assignments as documented by Dell.
  • Apply least privilege principles to local accounts to limit the capabilities of potential attackers.

Generated by OpenCVE AI on September 21, 2026 at 20:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description Dell Command | Monitor (DCM), versions prior to 10.13.2, contain an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Weaknesses CWE-732
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-21T19:38:20.015Z

Reserved: 2026-06-01T17:04:30.334Z

Link: CVE-2026-49811

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-21T20:17:25.660

Modified: 2026-09-21T20:17:25.660

Link: CVE-2026-49811

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T20:30:18Z

Weaknesses
  • CWE-732

    Incorrect Permission Assignment for Critical Resource