CVE-2026-71181: Low severity Dell Dell Update Package Framework vulnerability
Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell Update Package Frameworkto a version that resolves this vulnerability.Fixed in 26.07.03
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attacker needs local access and high privileges. The CVSS vector also indicates no user interaction is required.
Which versions are affected?
Dell Update Package Framework versions earlier than 26.07.03 are affected. Updating to version 26.07.03 or later addresses the affected version range described.
What could exploitation allow?
Successful exploitation could give the attacker filesystem access. The reported impact includes low integrity and availability effects, with no confidentiality impact indicated.