Description
Dell Server Update Utility, versions prior to 26.07.01, contains an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
Published: 2026-09-17
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Code Execution
Action: Immediate Patch
AI Analysis

Impact

Detected in the Dell Server Update Utility, versions before 26.07.01, the vulnerability is an uncontrolled search path element flaw. A local attacker with limited permissions can influence the path that the utility follows when locating shared libraries or executable components, which may result in arbitrary code execution under the utility’s process context. The flaw is listed as CWE-427.

Affected Systems

Affects Dell Driver Pack for Linux OS and Dell Driver Pack for Windows OS, along with the Dell Server Update Utility on Linux 64‑bit and Windows 64‑bit formats. Any installation of the update utility with a version older than 26.07.01 is vulnerable.

Risk and Exploitability

The CVSS score of 8.2 marks the flaw as high severity, but the EPSS score is not available and the vulnerability is not currently listed in the CISA KEV catalog. Exploitation requires local access and a low‑privileged user account; no remote vector is described. If the utility runs in a privileged context, an attacker could gain escalation to those privileges through the code execution path.

Generated by OpenCVE AI on September 17, 2026 at 20:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Dell Server Update Utility security update, version 26.07.01 or later, as provided in the Dell support knowledge base (DSA‑2026‑422).
  • Upgrade the Dell Driver Pack for Linux OS and Dell Driver Pack for Windows OS to the latest compatible versions that include the utility update.
  • If an immediate update is not possible, restrict execution of the Server Update Utility by blocking it from the system PATH or by removing the executable from the server.

Generated by OpenCVE AI on September 17, 2026 at 20:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Title Uncontrolled Search Path Element in Dell Server Update Utility Allows Local Code Execution

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell driver Pack For Linux Os
Dell driver Pack For Windows Os
Dell server Update Utility
Vendors & Products Dell
Dell driver Pack For Linux Os
Dell driver Pack For Windows Os
Dell server Update Utility

Thu, 17 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description Dell Server Update Utility, versions prior to 26.07.01, contains an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
Weaknesses CWE-427
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Dell Driver Pack For Linux Os Driver Pack For Windows Os Server Update Utility
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-19T14:21:53.052Z

Reserved: 2026-06-23T05:04:35.872Z

Link: CVE-2026-56795

cve-icon Vulnrichment

Updated: 2026-09-19T14:15:22.499Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T16:17:31.893

Modified: 2026-09-19T15:16:59.640

Link: CVE-2026-56795

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:30:17Z

Weaknesses
  • CWE-427

    Uncontrolled Search Path Element