Description
Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. This vulnerability is considered critical because it can be leveraged by an unauthenticated attacker to execute arbitrary code with root privileges. Successful exploitation may allow complete compromise of the vulnerable application and underlying operating system. Dell recommends customers upgrade at the earliest opportunity.
Published: 2026-10-06
Score: 9.6 Critical
EPSS: n/a
KEV: No
Impact: Remote code execution with root privileges
Action: Immediate Patch
AI Analysis

Impact

Dell System Update releases prior to version 2.3.0.0 contain a path traversal flaw that an unauthenticated attacker with remote access could exploit to gain filesystem read/write abilities. Successful exploitation can lead to arbitrary code execution and, as stated, potentially compromise the underlying operating system with root privileges, making it a critical vulnerability.

Affected Systems

The affected product is Dell System Update. All releases with a version number lower than 2.3.0.0 are vulnerable; newer builds are presumed patched.

Risk and Exploitability

The CVSS score of 9.6 ranks this flaw as critical, and although no EPSS score is published, the lack of public listing in CISA’s KEV catalog does not diminish its severity. An attacker does not need authentication and must simply reach the vulnerable component from a remote network location; the attack surface is therefore sizable for threats that can reach the Update service.

Generated by OpenCVE AI on October 6, 2026 at 19:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the Dell System Update 2.3.0.0 or later to eliminate the path traversal flaw
  • If an immediate upgrade is not possible, restrict network access to the System Update service so only trusted hosts can reach it
  • Remove any old or unused Dell System Update binaries from the system to prevent accidental use

Generated by OpenCVE AI on October 6, 2026 at 19:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Description Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. This vulnerability is considered critical because it can be leveraged by an unauthenticated attacker to execute arbitrary code with root privileges. Successful exploitation may allow complete compromise of the vulnerable application and underlying operating system. Dell recommends customers upgrade at the earliest opportunity.
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-10-06T19:46:54.531Z

Reserved: 2026-09-07T10:04:28.181Z

Link: CVE-2026-86360

cve-icon Vulnrichment

Updated: 2026-10-06T19:46:50.554Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:18:16.430

Modified: 2026-10-06T20:17:34.090

Link: CVE-2026-86360

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T19:45:04Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')