Description
Dell System Update, versions prior to 2.3.0.0, contains an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Published: 2026-10-06
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: Elevation of Privileges
Action: Apply Patch
AI Analysis

Impact

An improper access control flaw exists in Dell System Update, allowing a local attacker with low privileges to exploit the vulnerability. By bypassing normal authorization checks, the attacker can gain higher level privileges on the affected system. The flaw is categorized as CWE-284, reflecting unauthorized access to privileged resources.

Affected Systems

Dell System Update versions earlier than 2.3.0.0 are affected. All installations of the Dell System Update client that have not been upgraded to 2.3.0.0 or later remain vulnerable.

Risk and Exploitability

The CVSS score of 8.2 indicates a high severity risk. The EPSS score is not available, so the exact exploitation likelihood cannot be quantified, but the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local, requiring an attacker to have physical or local administrative access to the host. Once the privilege escalation is achieved, the attacker could install malicious software, access sensitive data, or further compromise the system.

Generated by OpenCVE AI on October 6, 2026 at 19:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Dell System Update to version 2.3.0.0 or later and apply any vendor-supplied security patches.
  • Ensure that only trusted administrators have local access; apply the principle of least privilege to local user accounts.
  • Monitor local system activity for suspicious authentication or privilege escalation events and enforce strict audit logging.

Generated by OpenCVE AI on October 6, 2026 at 19:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Dell System Update Allows Local Privilege Escalation

Tue, 06 Oct 2026 18:45:00 +0000

Type Values Removed Values Added
Description Dell System Update, versions prior to 2.3.0.0, contains an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-10-06T19:29:11.365Z

Reserved: 2026-09-07T10:04:28.181Z

Link: CVE-2026-86362

cve-icon Vulnrichment

Updated: 2026-10-06T19:27:04.010Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:18:16.717

Modified: 2026-10-06T20:17:34.193

Link: CVE-2026-86362

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T19:45:04Z

Weaknesses