Description
Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Published: 2026-08-19
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in Dell Command Update (DCU) versions prior to 5.7.1 and involves the deserialization of untrusted data. Exploitation of this flaw allows an adversary to execute arbitrary code within the context of the application, leading to the elevation of privileges on the affected system. The weakness is categorized under CWE‑502, indicating that untrusted data is deserialized without sufficient validation.

Affected Systems

Dell Command Update for Dell systems, any installation of the DCU software with a version earlier than 5.7.1. The vulnerability impacts any configuration where the DCU executable can be run by a local user without additional security controls.

Risk and Exploitability

With a CVSS score of 7.8, the risk level is moderate to high. The EPSS score is currently not available, and the vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. The likely attack vector is a local attacker who has low privileged access to the machine; because the flaw requires the DCU binary to be executed, the attacker would need to perform or trigger a local run of the application to achieve privilege escalation.

Generated by OpenCVE AI on August 19, 2026 at 16:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Dell Command Update to version 5.7.1 or later using the Dell Security Update for DCU available on Dell’s support site
  • If the update cannot be applied immediately, remove or disable the DCU application to prevent execution by local users
  • Restrict execution of DCU to administrative accounts only, ensuring that low privileged users do not have both read and execute permissions on the application

Generated by OpenCVE AI on August 19, 2026 at 16:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Title Deserialization of Untrusted Data in Dell Command Update Leading to Privilege Escalation

Wed, 19 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
Description Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-19T15:22:29.397Z

Reserved: 2026-06-01T17:04:30.334Z

Link: CVE-2026-49817

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-19T15:17:07.480

Modified: 2026-08-19T16:17:18.517

Link: CVE-2026-49817

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T17:00:12Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data