Impact
The vulnerability is an improper link resolution before file access in the Dell Update Package Framework. An attacker who already has high privilege on a local machine could follow symbolic or hard links to bypass file‑access controls and read or write arbitrary files on the system.
Affected Systems
Dell Update Package Framework versions earlier than 26.07.03 are affected. The vulnerability has been documented in Dell’s DSA‑2026‑417 security advisory.
Risk and Exploitability
The CVSS score of 3 indicates low severity, and the EPSS score of less than 1% reflects a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack vector is inferred to be local: it requires the attacker to have high privileged access on the affected machine, and remote exploitation is not suggested by the available information.
OpenCVE Enrichment