dell-technologiesCVE-2026-71179
Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability.
High7.3CVE-2026-71179 · Published Sep 16, 2026 · updated Sep 21, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Update Package Framework Vendor | < 26.07.03 or later | 26.07.03 or later |
Details and references
Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
- Severity from
- no source yet
- Weakness
- CWE-78