Description
Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges and Server-side request forgery.
Published: 2026-08-19
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell Command Update (DCU) versions before 5.7.1 include an Improper Restriction of XML External Entity Reference flaw (CWE-611). A low‑privileged user with local access could supply crafted XML input, causing the application to resolve external entities and thereby elevate privileges on the host and potentially perform server‑side request forgery to access internal resources.

Affected Systems

The vulnerability affects Dell Command Update software on Dell systems running any version prior to 5.7.1. Users running earlier releases of DCU are exposed unless updated.

Risk and Exploitability

With a CVSS score of 6.5 the issue is considered moderate‑to‑high severity. The EPSS score is < 1%, and the vulnerability is not listed in CISA KEV. The exploitation model requires local access by a low‑privileged account; an attacker would need to run DCU with malicious XML input, making remote exploitation unlikely but local privilege escalation possible.

Generated by OpenCVE AI on August 20, 2026 at 15:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Dell Command Update to version 5.7.1 or later using the Dell Security Advisory 2026-309
  • Configure the system to restrict local access to non‑privileged accounts and enforce least privilege for DCU execution
  • Maintain a schedule of Dell Patch Tuesday releases to ensure ongoing protection against related vulnerabilities

Generated by OpenCVE AI on August 20, 2026 at 15:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Title Dell Command Update XML External Entity Vulnerability Enabling Local Privilege Escalation

Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell dell Command Update (dcu)
Vendors & Products Dell
Dell dell Command Update (dcu)

Thu, 20 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title XML External Entity Vulnerability in Dell Command Update Enabling Privilege Escalation

Wed, 19 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title XML External Entity Vulnerability in Dell Command Update Enabling Privilege Escalation

Wed, 19 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Description Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges and Server-side request forgery.
Weaknesses CWE-611
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Dell Dell Command Update (dcu)
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-20T15:57:09.098Z

Reserved: 2026-07-29T11:04:32.678Z

Link: CVE-2026-67268

cve-icon Vulnrichment

Updated: 2026-08-20T15:51:56.689Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-08-19T15:17:51.893

Modified: 2026-08-20T16:17:49.260

Link: CVE-2026-67268

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T15:30:03Z

Weaknesses
  • CWE-611

    Improper Restriction of XML External Entity Reference