Dell security advisory (AV26-959)
Canadian Cyber Centre flags credential theft, weak permissions, and unquoted paths in Dell management tools.
Canadian Cyber Centre advisory AV26-959, dated September 23, 2026, covers multiple Dell management-tool flaws reported as of September 21. Dell Command PowerShell Provider before 2.10.2 is affected by credential theft via the PowerShell event log, and Dell Command Monitor before 10.13.2 has an incorrect permission assignment. A separate unquoted search path issue affects Dell SupportAssist, Dell Optimizer, Dell Trusted Device, and Dell Command Update; Dell Inventory Collector before 15.0.0 is also listed. No CVE IDs or active exploitation are stated.
- DCPP before 2.10.2 can expose credentials through PowerShell event logs.
- Dell Command Monitor before 10.13.2 assigns incorrect permissions to a critical resource.
- SupportAssist, Optimizer, Trusted Device, and Command Update have unquoted paths.
- Advisory AV26-959 cites Dell DSA-2026-379, DSA-2026-380, and DSA-2026-381.
Full article135 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-959
Date: September 23, 2026
As of September 21, 2026, Dell is affected by vulnerabilities in the following products:
- Dell Command Powershell Provider (DCPP)
- Prior to 2.10.2
- Dell Command Monitor (DCM)
- Prior to 10.13.2
- Dell Inventory Collector Client
- Prior to 15.0.0
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
- DSA-2026-379: Security Update for Dell Command | PowerShell Provider (DCPP) for a Credential Theft via PowerShell Event Log Vulnerability
- DSA-2026-380: Security Update for Dell Command | Monitor (DCM) for an Incorrect Permission Assignment for Critical Resource Vulnerability
- DSA-2026-381: Security Update for Dell SupportAssist for PCs (Home and Business), Dell Optimizer, Dell Trusted Device, Dell Command | Update for an Unquoted Search Path or Element Vulnerability
- Security Advisories, Notices and Resources
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/dell-security-advisory-av26-959