Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 21 Sep 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:dell:update_package_framework:*:*:*:*:*:*:*:* |
Fri, 18 Sep 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dell
Dell update Package Framework |
|
| Vendors & Products |
Dell
Dell update Package Framework |
Fri, 18 Sep 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | OS Command Injection in Dell Update Package Framework Enabling Local Privilege Escalation |
Wed, 16 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2026-09-17T03:57:06.805Z
Reserved: 2026-08-04T23:04:32.436Z
Link: CVE-2026-71179
Updated: 2026-09-16T17:27:18.407Z
Status : Analyzed
Published: 2026-09-16T17:18:05.970
Modified: 2026-09-21T17:30:48.000
Link: CVE-2026-71179
No data.
OpenCVE Enrichment
Updated: 2026-09-18T04:30:03Z