CVE-2026-56795: High severity Dell Server Update Utility vulnerability
Dell Server Update Utility, versions prior to 26.07.01, contains an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell Server Update Utilityto a version that resolves this vulnerability.Fixed in 26.07.01
Event History
Frequently Asked Questions
Which systems are exposed to exploitation?
Systems running Dell Server Update Utility versions earlier than 26.07.01 are affected. Exploitation requires local access and an existing low-privileged account.
Does exploitation require user interaction?
Yes. The CVSS vector indicates user interaction is required, so a local low-privileged attacker would need a user to perform an action as part of exploitation.
What is the remediation?
Update Dell Server Update Utility to version 26.07.01 or later. The provided information does not specify an alternative mitigation if updating is not immediately possible.