Skip to content
dell-technologiesCVE-2026-71182

Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability.

Low3.0CVE-2026-71182 · Published Sep 16, 2026 · updated Sep 21, 2026

Source advisory

Affected versions

PackageAffectedFixed in
Update Package Framework
Vendor
< 26.07.03 or later26.07.03 or later
Details and references

Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.

CVSS 3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L
Severity from
no source yet
Weakness
CWE-59

More dell-technologies advisories

All
DateAdvisory
Sep 15Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Cryptographic Step vulnerability.
CVE-2026-81235High8.0fixed in Wyse Management Suite WMS 2605.0.3.683
Sep 15Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability.
CVE-2026-81236High8.6fixed in Wyse Management Suite WMS 2605.0.3.683
Sep 15Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Improper Authentication vulnerability.
CVE-2026-81237Medium6.5fixed in Wyse Management Suite WMS 2605.0.3.683
Sep 15Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Authentication for Critical Function vulnerability.
CVE-2026-81238High7.5fixed in Wyse Management Suite WMS 2605.0.3.683
Sep 15Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability.
CVE-2026-81239High8.6fixed in Wyse Management Suite WMS 2605.0.3.683
Sep 15Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability.
CVE-2026-81240High8.6fixed in Wyse Management Suite WMS 2605.0.3.683

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.