Description
Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.
Published: 2026-09-16
Score: 3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized local file system access
Action: Apply patch
AI Analysis

Impact

The vulnerability is an improper link resolution before file access in the Dell Update Package Framework. An attacker who already has high privilege on a local machine could follow symbolic or hard links to bypass file‑access controls and read or write arbitrary files on the system.

Affected Systems

Dell Update Package Framework versions earlier than 26.07.03 are affected. The vulnerability has been documented in Dell’s DSA‑2026‑417 security advisory.

Risk and Exploitability

The CVSS score of 3 indicates low severity, and the EPSS score of less than 1% reflects a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack vector is inferred to be local: it requires the attacker to have high privileged access on the affected machine, and remote exploitation is not suggested by the available information.

Generated by OpenCVE AI on September 18, 2026 at 01:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Dell Update Package Framework version 26.07.03 or later as provided in DSA‑2026‑417.
  • Restrict local high‑privileged accounts to the minimum required for system operations, ensuring that only trusted administrators can access the system at that level.
  • Conduct an audit of local accounts to verify that no unauthorized high‑privilege credentials exist and monitor file‑access activity for anomalies.

Generated by OpenCVE AI on September 18, 2026 at 01:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:dell:update_package_framework:*:*:*:*:*:*:*:*

Fri, 18 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell update Package Framework
Vendors & Products Dell
Dell update Package Framework

Fri, 18 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Title High-Privilege Local Filesystem Access via Improper Link Resolution in Dell Update Package Framework

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.
Weaknesses CWE-59
References
Metrics cvssV3_1

{'score': 3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Dell Update Package Framework
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-16T18:34:57.356Z

Reserved: 2026-08-04T23:04:32.436Z

Link: CVE-2026-71181

cve-icon Vulnrichment

Updated: 2026-09-16T18:18:48.100Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T17:18:06.610

Modified: 2026-09-21T17:30:31.517

Link: CVE-2026-71181

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T04:30:03Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')