Description
Dell Update Package Framework, versions prior to 26.07.03, contains a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote execution.
Published: 2026-09-16
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Dell Update Package Framework versions released before 26.07.03 contain a stack-based buffer overflow that could allow an unauthenticated attacker with adjacent network access to execute arbitrary code remotely. This flaw, classified as CWE-121, may compromise confidentiality, integrity, and availability of the affected system by providing the attacker with a foothold to run malicious payloads. The CVE description indicates that exploitation would result in remote execution, revealing a severe impact on system security.

Affected Systems

All installations of Dell Update Package Framework running a pre‑26.07.03 version are impacted. The vulnerability applies to any system that hosts this framework, regardless of operating environment, as soon as it receives updates from an unauthenticated source on the same local network.

Risk and Exploitability

The CVSS score of 6.5 puts the vulnerability in the medium severity range, while the EPSS score of less than 1% suggests a very low probability of exploitation at this time. The attack vector would be remote, requiring the attacker to be in the same local network segment that can contact the Update Package Framework service. Although the vulnerability is not listed in CISA’s KEV catalog, its potential for remote code execution makes immediate remediation advisable.

Generated by OpenCVE AI on September 18, 2026 at 02:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Dell Update Package Framework security update 26.07.03 or later from Dell’s support site.
  • Restrict unauthenticated access to the Update Package Framework by configuring firewall rules or network segmentation to limit adjacent network reach.
  • Enable operating system stack protection features such as stack canaries, address space layout randomization, and data execution prevention to mitigate buffer overflow exploitation.

Generated by OpenCVE AI on September 18, 2026 at 02:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:dell:update_package_framework:*:*:*:*:*:*:*:*

Fri, 18 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell update Package Framework
Vendors & Products Dell
Dell update Package Framework

Fri, 18 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Title Stack-Based Buffer Overflow in Dell Update Package Framework Enables Remote Execution

Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Dell Update Package Framework, versions prior to 26.07.03, contains a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote execution.
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Dell Update Package Framework
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-17T11:48:11.631Z

Reserved: 2026-09-07T10:04:28.181Z

Link: CVE-2026-86358

cve-icon Vulnrichment

Updated: 2026-09-16T17:30:34.275Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T17:18:16.310

Modified: 2026-09-21T17:51:45.927

Link: CVE-2026-86358

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T04:30:03Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow