CVE-2026-86359
moderateIncorrect Default Permissions in Dell Repository Manager before 3.5.2
Dell Repository Manager (DRM) versions prior to 3.5.2 ship with incorrect default permissions (CWE-276) on files or components of the application, leaving them writable or usable by accounts that should not have that level of access. A low-privileged attacker who already has some form of remote access to the system running DRM could leverage these misconfigured permissions to elevate privileges, a path reflected in the high-severity CVSS score of 8.5 with network attack vector, high attack complexity, and a changed scope indicating impact beyond the vulnerable component itself. Successful exploitation could yield high confidentiality, integrity, and availability impact on the host and potentially related resources. Organizations are affected if they run affected DRM versions, typically on administrator workstations or management servers used to build and host Dell update repositories. Exploitation status: this flaw is not listed in CISA's KEV catalog, no public proof-of-concept is known, and there are no reports of in-the-wild exploitation.
What to do: Upgrade to Dell Repository Manager 3.5.2 or later, which corrects the default permissions. In the meantime, restrict network and local access to hosts running DRM to trusted administrative users, and audit permissions on DRM installation directories, services, and scheduled tasks for overly permissive settings. Since exploitation requires a low-privileged foothold with remote access, prioritize patching hosts reachable from broader networks or shared user environments.
| Dell Repository Manager | All versions prior to 3.5.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell Repository Manager, versions prior to 3.5.2, contains an Incorrect Default Permissions vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
- Weakness
- CWE-276
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.