CVE-2026-49810: High severity Dell Dell Command PowerShell Provider (DCPP) vulnerability
Dell Command Powershell Provider (DCPP), versions prior to 2.10.2 contain an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell Command Powershell Provider (DCPP)to a version that resolves this vulnerability.Fixed in 2.10.2
Event History
Frequently Asked Questions
Which installations are affected?
Dell Command PowerShell Provider versions earlier than 2.10.2 are affected. Systems running version 2.10.2 or later are not identified as affected in the provided information.
What level of access does an attacker need?
An attacker needs local access and low privileges. No user interaction is required according to the supplied CVSS vector.
What is the potential impact?
The vulnerability can expose sensitive information through log files. The provided severity vector also rates confidentiality, integrity, and availability impact as high.