Skip to content
Dell TechnologiesCVE-2026-71181

Dell Technologies Update Package Framework: link following

Low3.0CVE-2026-71181 · Published Sep 16, 2026 · updated Sep 21, 2026

Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.

Dell Technologies advisory

Affected versions

PackageAffectedFixed in
Update Package Framework
Product
< 26.07.03 or later26.07.03 or later
Details and references

More Dell Technologies advisories

All Dell Technologies
Advisory
Dell Technologies Update Package Framework: stack buffer overflow
Medium6.5Sep 16
Dell Technologies Repository Manager: insecure permissions
High8.5Sep 16
Dell Update Package Framework
High8.2Sep 16
Dell Technologies Update Package Framework: link following
Low3.0Sep 16
Dell Technologies Update Package Framework: command injection
High7.3Sep 16
Dell Technologies ObjectScale: insecure permissions
Medium5.5Sep 16

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.