Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.6

CVE-2026-86360: Dell System Update before 2.3 permits remote file access

CVE-2026-86360 · published 3 days ago
Summary

The Dell System Update tool versions earlier than 2.3.0.0 let a person on the network reach files and run code on the computer with full privileges. This could let an attacker take control of the system. Install the latest Dell System Update version as soon as possible to close the gap.

What to do
  • Update dell system update to version 2.3.0.0 or later or later.
Affected software
VendorProductAffected versions
dell system update < 2.3.0.0 or later
Original advisory text
Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote acce...
Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. This vulnerability is considered critical because it can be leveraged by an unauthenticated attacker to execute arbitrary code with root privileges. Successful exploitation may allow complete compromise of the vulnerable application and underlying operating system. Dell recommends customers upgrade at the earliest opportunity.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.6 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-22Path Traversal
Timeline
Published6 Oct 2026
Updated7 Oct 2026
First seen6 Oct 2026
Sources
CVE-2026-86360 · MITRE
Track software like this
Free during beta