Description
Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Published: 2026-09-16
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in Dell Update Package Framework is an OS Command Injection flaw that allows a low‑privileged local user to execute arbitrary operating system commands. By exploiting this flaw, an attacker can elevate their privileges, potentially gaining full system control. The weakness corresponds to CWE‑78.

Affected Systems

Dell Update Package Framework versions older than 26.07.03 are affected. The vulnerability applies to all installations of the framework using these legacy releases.

Risk and Exploitability

The CVSS score of 7.3 indicates a high severity, while the EPSS score of less than 1% suggests only a very low probability of widespread exploitation at this time. The flaw is not listed in the CISA KEV catalog, but it can be exploited locally by any user who has basic access to the system. The attack vector is local and requires no network connectivity, making it important for environments where users have unrestricted local access.

Generated by OpenCVE AI on September 18, 2026 at 02:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Dell security update for Update Package Framework version 26.07.03 or later as described in the Dell security advisory.
  • Restrict local user accounts from executing administrative commands or running the Update Package Framework unless they are explicitly required for their role.
  • Enable logging and auditing for Update Package Framework execution and review logs for suspicious activity.

Generated by OpenCVE AI on September 18, 2026 at 02:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:dell:update_package_framework:*:*:*:*:*:*:*:*

Fri, 18 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell update Package Framework
Vendors & Products Dell
Dell update Package Framework

Fri, 18 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Dell Update Package Framework Enabling Local Privilege Escalation

Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Update Package Framework
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-17T03:57:06.805Z

Reserved: 2026-08-04T23:04:32.436Z

Link: CVE-2026-71179

cve-icon Vulnrichment

Updated: 2026-09-16T17:27:18.407Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T17:18:05.970

Modified: 2026-09-21T17:30:48.000

Link: CVE-2026-71179

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T04:30:03Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')