CVE-2026-71179
massOS Command Injection Elevation-of-Privilege in Dell Update Package Framework
Dell Update Package Framework versions prior to 26.07.03 contain an OS command injection flaw (CWE-78) in which special elements are improperly neutralized before being passed to the operating system. A local, low-privileged attacker can trigger the vulnerability, and the CVSS vector (UI:R) indicates user interaction is required to exploit it. Successful exploitation executes arbitrary OS commands in the context of the update framework, elevating the attacker's privileges with high impact on confidentiality, integrity, and availability. Any Dell client system running the affected framework — typically deployed as part of Dell's client update tooling on consumer and commercial PCs — is affected. No public proof of concept is known and the flaw is not in CISA KEV, so exploitation is not currently observed.
What to do: Upgrade Dell Update Package Framework to version 26.07.03 or later, available via Dell's support site or Dell Command | Update / Dell Update channels. Because exploitation requires local low-privileged access and user interaction, prioritize patching shared, multi-user, and kiosk-style endpoints, and verify the installed framework version on managed Dell clients.
| Dell Update Package Framework | All versions prior to 26.07.03 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.