CVE-2026-71179
Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
- Published Sep 16, 2026
- CVSS 7.8 high
- 0.6% chance of exploitation in the next 30 days (EPSS)
- A fix is available