Description
Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.
Published: 2026-08-19
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell Command Update versions prior to 5.7.1 contain an Incorrect Default Permissions flaw. An attacker with low privileges and local access could gain access to the host’s filesystem, potentially reading, modifying, or deleting files that should be protected. The vulnerability arises from improper file permission settings, allowing local users to bypass expected restrictions.

Affected Systems

The affected product is Dell Command Update (DCU) sold by Dell. Versions earlier than 5.7.1 are impacted; any system using those older releases is at risk. The vulnerability applies to all installations of DCU that store configuration files or binaries with overly permissive permissions.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity for local privilege escalation. EPSS data is not available, so the likelihood of exploitation in the wild is unknown, but the issue is not listed in the CISA KEV catalog. The attack requires local access and low privileges, meaning it could be used during a lateral movement or by an insider. Because the flaw involves default permission settings, exploitation requires no special code execution; the attacker simply leverages existing files on the system.

Generated by OpenCVE AI on August 19, 2026 at 17:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dell Command Update to version 5.7.1 or later to receive the patch that corrects default permissions
  • Verify that the DCU installation directory and its files are owned by the root or system user and have permissions set to 640 or 700, as appropriate
  • Conduct a local privilege review to ensure that no unprivileged accounts have elevated access to the DCU files or directories after the update

Generated by OpenCVE AI on August 19, 2026 at 17:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Incorrect Default Permissions in Dell Command Update

Wed, 19 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Description Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.
Weaknesses CWE-276
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-19T15:03:14.331Z

Reserved: 2026-07-01T11:04:36.019Z

Link: CVE-2026-58564

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-19T15:17:12.980

Modified: 2026-08-19T15:17:12.980

Link: CVE-2026-58564

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T17:45:03Z

Weaknesses
  • CWE-276

    Incorrect Default Permissions