Description
Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
Published: 2026-08-19
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Dell Command Update is a Missing Authorization flaw that permits a low‑privileged local user to gain unauthorized access to administrative functionalities. Classified as CWE‑862, the issue could let an attacker execute privileged actions or alter system settings without proper authentication.

Affected Systems

Affecting Dell Command Update (DCU) versions prior to 5.7.1; users running any DCU release older than 5.7.1 are potentially exposed.

Risk and Exploitability

The CVSS score of 7.3 indicates moderate to high risk. Exploitation requires local access by a low‑privileged user, making it relatively feasible for internal threat actors. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, yet the missing authorization still permits local privilege escalation and unauthorized configuration changes.

Generated by OpenCVE AI on August 19, 2026 at 17:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Dell Security Update Advisory (DSA‑2026‑309) to upgrade DCU to version 5.7.1 or later.
  • If an immediate upgrade is not possible, restrict local administrative privileges for DCU or isolate affected systems from the network.
  • Continuously monitor system logs for unauthorized attempts to use DCU functions without proper authentication.

Generated by OpenCVE AI on August 19, 2026 at 17:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Missing Authorization in Dell Command Update Enables Local Unauthorized Access

Wed, 19 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Description Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-19T15:18:34.804Z

Reserved: 2026-07-01T11:04:36.018Z

Link: CVE-2026-58562

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-19T15:17:12.603

Modified: 2026-08-19T16:18:09.263

Link: CVE-2026-58562

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T17:30:16Z

Weaknesses