ZeroHour

CVE-2026-86359

moderate

Incorrect Default Permissions in Dell Repository Manager before 3.5.2

CVSS 3.1
8.5 high
EPSS
Published
()
Modified
AI analysis

Dell Repository Manager (DRM) versions prior to 3.5.2 ship with incorrect default permissions (CWE-276) on files or components of the application, leaving them writable or usable by accounts that should not have that level of access. A low-privileged attacker who already has some form of remote access to the system running DRM could leverage these misconfigured permissions to elevate privileges, a path reflected in the high-severity CVSS score of 8.5 with network attack vector, high attack complexity, and a changed scope indicating impact beyond the vulnerable component itself. Successful exploitation could yield high confidentiality, integrity, and availability impact on the host and potentially related resources. Organizations are affected if they run affected DRM versions, typically on administrator workstations or management servers used to build and host Dell update repositories. Exploitation status: this flaw is not listed in CISA's KEV catalog, no public proof-of-concept is known, and there are no reports of in-the-wild exploitation.

What to do: Upgrade to Dell Repository Manager 3.5.2 or later, which corrects the default permissions. In the meantime, restrict network and local access to hosts running DRM to trusted administrative users, and audit permissions on DRM installation directories, services, and scheduled tasks for overly permissive settings. Since exploitation requires a low-privileged foothold with remote access, prioritize patching hosts reachable from broader networks or shared user environments.

Affected
Dell Repository ManagerAll versions prior to 3.5.2
Estimated exposure
moderatelikely on the order of tens of thousands of installations worldwide (admin workstations/management servers running DRM) — No public install telemetry exists for this optional, freely downloadable Dell utility, so the estimate is based on deployment patterns: DRM is widely used by enterprises managing Dell PowerEdge fleets, but it is typically installed on a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell Repository Manager, versions prior to 3.5.2, contains an Incorrect Default Permissions vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

Weakness
CWE-276
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.