Description
Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.
Published: 2026-09-16
Score: 3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Local Filesystem Access
Action: Apply Patch
AI Analysis

Impact

The Dell Update Package Framework contains an Improper Link Resolution Before File Access vulnerability (CWE‑59). A local attacker with high privileges could manipulate the framework to resolve arbitrary links and then access or read files that the framework process can reach. This could result in unintended disclosure of system files or configuration data, compromising confidentiality of sensitive files.

Affected Systems

Versions of the framework released before 26.07.03 are affected. The vendor, Dell, identifies this as a Update Package Framework update package. Systems running these earlier versions should be reviewed to confirm compliance.

Risk and Exploitability

The CVSS score of 3 indicates low severity overall, and the EPSS score of less than 1% shows a low likelihood of exploitation in the wild. The vulnerability is not currently marked in the CISA KEV catalog. Exploitation requires local access and high privileges, limiting the attack surface to compromised accounts or physical access. If a local privilege escalation has already occurred, this flaw provides a straightforward path to read arbitrary files in the system.

Generated by OpenCVE AI on September 18, 2026 at 01:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Dell Update Package Framework to version 26.07.03 or later to remove the improper link resolution flaw.
  • Verify that older update packages are uninstalled or disabled to prevent accidental execution.
  • Restrict local user privileges, ensuring only trusted accounts can install or run the update framework.

Generated by OpenCVE AI on September 18, 2026 at 01:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:dell:update_package_framework:*:*:*:*:*:*:*:*

Fri, 18 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell update Package Framework
Vendors & Products Dell
Dell update Package Framework

Fri, 18 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Title Dell Update Package Framework Improper Link Resolution Allows Local Privileged Filesystem Access

Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.
Weaknesses CWE-59
References
Metrics cvssV3_1

{'score': 3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Dell Update Package Framework
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-16T17:28:01.061Z

Reserved: 2026-08-04T23:04:32.437Z

Link: CVE-2026-71182

cve-icon Vulnrichment

Updated: 2026-09-16T17:27:56.945Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T17:18:06.753

Modified: 2026-09-21T17:30:22.093

Link: CVE-2026-71182

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T04:30:03Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')