Dell TechnologiesCVE-2026-41121
Dell Technologies Device Management Agent: link following
High7.3CVE-2026-41121 · Published Jul 1, 2026 · updated Jul 6, 2026
Dell Device Management Agent, versions prior to DDMA 26.05, contain an Improper Link Resolution Before File Access ('Link Following’) vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Device Management Agent Product | < 26.05 | 26.05 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-59
More Dell Technologies advisories
All Dell Technologies| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 3 | Dell Technologies PowerProtect Data Domain: link following | Medium4.4 | 8.7.0.0 or later+3 more |
| Jul 3 | Dell Technologies PowerProtect Data Domain: insecure permissions | Medium4.4 | 8.7.0.0 or later+3 more |
| Jul 3 | Dell Technologies PowerProtect Data Domain: path traversal | Low2.3 | 8.8.0.0 or later+3 more |
| Jul 3 | Dell Technologies PowerProtect Data Domain: improper access control | Medium4.3 | 8.7.0.0 or later+3 more |
| Jul 3 | Dell Technologies PowerProtect Data Domain: command injection | Medium6.5 | 8.8.0.0 or later+3 more |
| Jul 3 | Dell Technologies Alienware 16 Area-51 AA16250: authentication bypass | Medium5.3 | Inspiron 15 3520 1.41.0 or later+10 more |