CVE-2026-67267: Medium severity Dell Command Update (DCU) vulnerability
Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell Command Update (DCU)to a version that resolves this vulnerability.Fixed in 5.7.1
Event History
Frequently Asked Questions
Who is exposed to this issue?
Systems running Dell Command Update versions earlier than 5.7.1 are affected. Exploitation requires local access and a low-privileged account, so remotely unauthenticated attackers are not described as being able to exploit it.
What access does an attacker need, and what is the impact?
An attacker needs local access with low privileges and does not require user interaction. Successful exploitation may disclose sensitive system information; integrity and availability impacts are not identified.