Description
Dell System Update, versions prior to 2.3.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Published: 2026-10-06
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: Elevation of Privileges
Action: Immediate Patch
AI Analysis

Impact

Dell System Update contains an Incorrect Permission Assignment for Critical Resource vulnerability that allows a low‑privileged local attacker to gain elevated privileges. The flaw arises when critical system files are assigned permissions that unintentionally grant broader access to non‑administrative users, enabling the attacker to modify or execute privileged operations. This weakness is identified as CWE‑732 and results in potential unauthorized escalation of privileges within the affected system.

Affected Systems

The affected product is Dell System Update, specifically all releases prior to version 2.3.0.0. Systems running any such earlier build are vulnerable regardless of the underlying operating system. Administrators should verify the installed version and plan a patch if a vulnerable build is in use.

Risk and Exploitability

With a CVSS score of 8.2, the vulnerability is considered high severity, though its EPSS score is not available. It is not currently listed in the CISA KEV catalog. The attack vector is local, requiring an attacker to have low‑privileged access on the same machine. Once exploited, the attacker can elevate privileges and potentially perform arbitrary actions with elevated rights. Prompt remediation is recommended.

Generated by OpenCVE AI on October 6, 2026 at 19:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Dell System Update version 2.3.0.0 or later following Dell's security advisory DSA 2026‑324.
  • Remove or disable any local accounts that are not required to reduce the number of users who might exploit permission issues.
  • Enforce the principle of least privilege by reviewing and tightening file system permissions on critical resources, ensuring that only administrators have access.

Generated by OpenCVE AI on October 6, 2026 at 19:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
Title Elevation of Privileges in Dell System Update via Incorrect Permission Assignment

Tue, 06 Oct 2026 18:45:00 +0000

Type Values Removed Values Added
Description Dell System Update, versions prior to 2.3.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Weaknesses CWE-732
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-10-06T18:21:11.364Z

Reserved: 2026-09-07T10:04:28.181Z

Link: CVE-2026-86361

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:18:16.567

Modified: 2026-10-06T19:58:37.060

Link: CVE-2026-86361

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T19:45:04Z

Weaknesses
  • CWE-732

    Incorrect Permission Assignment for Critical Resource