Description
Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Published: 2026-08-19
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Deserialization of Untrusted Data flaw in Dell Command Update that can be triggered by a low‑privileged local user. By crafting malicious input, the attacker can gain elevated rights on the system, potentially allowing full control over the affected machine. This flaw corresponds to CWE‑502 and, if exploited, could compromise the confidentiality, integrity, or availability of local resources.

Affected Systems

Dell Command Update (DCU) versions before 5.7.1 are vulnerable.

Risk and Exploitability

This flaw has a CVSS score of 7.8, indicating high severity. The EPSS score of 0.00113 indicates an extremely low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalogue. Since the description specifies a low‑privileged local user as the attacker, the most likely attack vector is a local exploitation path; remote exploitation is not suggested by the information provided. Because the flaw involves deserialization of untrusted data, a successful attack would enable an attacker to execute arbitrary code or commands within the context of the application, effectively escalating privileges on the host.

Generated by OpenCVE AI on August 20, 2026 at 15:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Replace Dell Command Update with version 5.7.1 or later to eliminate the deserialization flaw.
  • After updating, restart the DCU service or the host to ensure the new binary loads correctly.
  • If an update cannot be applied immediately, prevent execution of older DCU binaries using file‑system permissions or application whitelisting tools, and monitor for suspicious activity.

Generated by OpenCVE AI on August 20, 2026 at 15:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell command Update
CPEs cpe:2.3:a:dell:command_update:*:*:*:*:*:*:*:*
Vendors & Products Dell command Update

Fri, 21 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Deserialization of Untrusted Data in Dell Command Update

Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell dell Command Update (dcu)
Vendors & Products Dell
Dell dell Command Update (dcu)

Thu, 20 Aug 2026 03:00:00 +0000

Type Values Removed Values Added
Title Deserialization Vulnerability in Dell Command Update Allows Local Privilege Escalation

Wed, 19 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Deserialization Vulnerability in Dell Command Update Allows Local Privilege Escalation

Wed, 19 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
Description Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Command Update Dell Command Update (dcu)
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-20T15:22:14.647Z

Reserved: 2026-06-01T17:04:30.334Z

Link: CVE-2026-49816

cve-icon Vulnrichment

Updated: 2026-08-20T14:46:50.968Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T15:17:07.337

Modified: 2026-08-21T13:40:57.000

Link: CVE-2026-49816

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T16:00:05Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data