Description
Dell Update Package Framework, versions prior to 26.07.03, contains an Unchecked Return Value vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Published: 2026-09-16
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the Dell Update Package Framework before version 26.07.03. An unchecked return value allows a local user with low privileges to trigger context‑dependent actions that ultimately raise privileges. This weakness maps to CWE‑252 and can result in unauthorized system access and data tampering.

Affected Systems

All Dell hosts that run the Update Package Framework earlier than 26.07.03 are affected. The flaw applies to the component distributed by Dell, so any Dell machine that relies on this framework before the specified release is likely impacted.

Risk and Exploitability

The CVSS score of 8.2 indicates high severity, while the EPSS score under 1% signals a low probability of exploitation. The vulnerability is not currently listed in the CISA KEV catalog. Because the flaw requires local access, an attacker must be able to log on or maintain a local session, but exploitation can lead to privilege escalation and potentially full administrative control over the system.

Generated by OpenCVE AI on September 18, 2026 at 01:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Dell Update Package Framework version 26.07.03 or later to remove the unchecked return value flaw.
  • If an immediate update is not feasible, restrict local user privileges and remove unnecessary execution rights for the Update Package Framework.
  • Monitor for suspicious local activity and enforce least privilege to limit potential exploitation.

Generated by OpenCVE AI on September 18, 2026 at 01:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:dell:update_package_framework:*:*:*:*:*:*:*:*

Fri, 18 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell update Package Framework
Vendors & Products Dell
Dell update Package Framework

Fri, 18 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Title Unchecked Return Value Vulnerability Enabling Privilege Escalation in Dell Update Package Framework

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description Dell Update Package Framework, versions prior to 26.07.03, contains an Unchecked Return Value vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Weaknesses CWE-252
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Dell Update Package Framework
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-17T11:39:25.121Z

Reserved: 2026-08-04T23:04:32.436Z

Link: CVE-2026-71180

cve-icon Vulnrichment

Updated: 2026-09-17T11:32:23.076Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T17:18:06.100

Modified: 2026-09-21T17:30:41.560

Link: CVE-2026-71180

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T04:30:03Z

Weaknesses