Description
Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Published: 2026-08-19
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability occurs in Dell Command Update (DCU), versions before 5.7.1, due to a Missing Authorization flaw. The flaw allows a local attacker with no or very limited privileges to spoof or bypass authorization checks and gain level access. This can result in the attacker performing actions normally restricted to administrative users. The weakness is identified as CWE-862 and can compromise confidentiality, integrity, and availability of the system. The CVE score of 8.8 places it in the high severity range for privilege escalation issues.

Affected Systems

All installations of Dell Command Update running a version older than 5.7.1 are affected. The product is distributed by Dell and is used to keep Dell firmware and drivers up to date on a local machine. No specific operating system versions are listed, so any host that runs an affected DCU version is vulnerable.

Risk and Exploitability

The CVSS score of 8.8 reflects a high severity of privilege escalation. The EPSS score of 0.00093 indicates a very low but non‑zero probability of exploitation. The vulnerability is not listed in CISA KEV, suggesting no known active exploitation. The attack vector is inferred to be local, requiring low‑privilege local access; once exploited, the attacker can elevate privileges to full control of the host.

Generated by OpenCVE AI on August 20, 2026 at 15:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dell Command Update to version 5.7.1 or later
  • If an upgrade is not immediately possible, uninstall Dell Command Update to eliminate the vulnerable component
  • Restrict local user accounts to administrative rights only when executing Dell Command Update, ensuring standard users have no write permission to the DCU installation files

Generated by OpenCVE AI on August 20, 2026 at 15:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell command Update
CPEs cpe:2.3:a:dell:command_update:*:*:*:*:*:*:*:*
Vendors & Products Dell command Update

Thu, 20 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Title Elevation of Privileges Vulnerability in Dell Command Update

Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell dell Command Update (dcu)
Vendors & Products Dell
Dell dell Command Update (dcu)

Thu, 20 Aug 2026 03:00:00 +0000

Type Values Removed Values Added
Title Elevated Privileges via Missing Authorization in Dell Command Update

Wed, 19 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Title Elevated Privileges via Missing Authorization in Dell Command Update

Wed, 19 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Description Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Dell Command Update Dell Command Update (dcu)
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-20T15:57:09.415Z

Reserved: 2026-07-01T11:04:36.019Z

Link: CVE-2026-58565

cve-icon Vulnrichment

Updated: 2026-08-20T15:52:08.220Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T15:17:13.280

Modified: 2026-08-21T13:40:43.610

Link: CVE-2026-58565

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T15:45:03Z

Weaknesses