CVE-2026-58564: High severity Dell Command Update (DCU) vulnerability
Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell Command Update (DCU)to a version that resolves this vulnerability.Fixed in 5.7.1 - Compensating control
If you cannot immediately upgrade, restrict local access to Dell Command Update (DCU) hosts (e.g., limit who can access the system where DCU is installed) to reduce the risk from low-privileged local attackers.
Event History
Frequently Asked Questions
Who is exposed to this issue?
Systems running Dell Command Update versions earlier than 5.7.1 are affected. Exploitation requires local access and low-privileged access to the system.
What access does an attacker need, and what could they gain?
An attacker must already be able to run actions locally with low privileges; no user interaction is required. Successful exploitation could lead to filesystem access.
What is the remediation?
Update Dell Command Update to version 5.7.1 or later.