CVE-2026-23857: High severity Dell Dell Update Package (DUP) Framework vulnerability
Published Feb 12, 2026
·Updated
Dell Update Package (DUP) Framework, versions 23.12.00 through 24.12.00, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Affected Software
2 affected components
Dell Dell Update Package (DUP) Framework>=23.12.00<=24.12.00
Dell Update Package Framework>=23.12.00<25.02.00
Event History
Feb 12, 2026
CVE Published
via MITRE·02:05 AM
Data Sourced
via MITRE·02:05 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-23857?
CVE-2026-23857 is classified as a low severity vulnerability.
2
How do I fix CVE-2026-23857?
To resolve CVE-2026-23857, update your Dell Update Package (DUP) Framework to a version above 24.12.00.
3
Who is affected by CVE-2026-23857?
CVE-2026-23857 affects users of Dell Update Package (DUP) Framework versions 23.12.00 through 24.12.00.
4
What type of vulnerability is CVE-2026-23857?
CVE-2026-23857 is an Improper Handling of Insufficient Permissions or Privileges vulnerability.
5
Can CVE-2026-23857 be exploited remotely?
No, CVE-2026-23857 requires local access to exploit.