Description
Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Published: 2026-08-19
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell Command Update versions prior to 5.7.1 allow a local attacker to follow an improperly resolved link, resulting in unauthorized file access. This vulnerability can be abused to escape normal privilege boundaries on the system, potentially granting the attacker higher privileges than it originally held. The flaw aligns with CWE-59, which captures unsafe relative path resolution leading to unintended file access.

Affected Systems

Dell Command Update (DCU) software from Dell, affecting all deployments using a release older than 5.7.1. Users running these versions are susceptible, regardless of the motherboard or OEM environment, as the vulnerable component operates with local machine resources.

Risk and Exploitability

The vulnerability is rated a CVSS score of 6.6, indicating moderate severity, and it is not listed in the CISA KEV catalog. The EPSS score of 0.00123 indicates a very low probability of exploitation. Although the local attack vector and low privilege requirement mean an attacker who can access the machine locally may trigger the flaw to elevate privileges, the overall likelihood remains low.

Generated by OpenCVE AI on August 20, 2026 at 15:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dell Command Update to version 5.7.1 or later to address the link‑following flaw.
  • If an upgrade is not immediately possible, uninstall or disable the DCU component until the vulnerability is patched.
  • Limit local user privileges and monitor for anomalous file‑access activity as an additional safeguard.

Generated by OpenCVE AI on August 20, 2026 at 15:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell command Update
CPEs cpe:2.3:a:dell:command_update:*:*:*:*:*:*:*:*
Vendors & Products Dell command Update

Thu, 20 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Improper Link Resolution in Dell Command Update Leading to Privilege Escalation

Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell dell Command Update (dcu)
Vendors & Products Dell
Dell dell Command Update (dcu)

Thu, 20 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Title Elevated Privileges via Improper Link Resolution in Dell Command Update

Wed, 19 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Elevated Privileges via Improper Link Resolution in Dell Command Update

Wed, 19 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
Description Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Weaknesses CWE-59
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L'}


Subscriptions

Dell Command Update Dell Command Update (dcu)
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-21T16:16:55.390Z

Reserved: 2026-06-23T05:04:35.872Z

Link: CVE-2026-56796

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T15:17:11.800

Modified: 2026-08-21T17:16:32.080

Link: CVE-2026-56796

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T16:00:05Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')