CVE-2026-71182: Low severity Dell Dell Update Package Framework vulnerability
Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell Update Package Frameworkto a version that resolves this vulnerability.Fixed in 26.07.03
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Systems running Dell Update Package Framework versions earlier than 26.07.03 are affected. Exploitation requires local access and high privileges, so remote-only attackers and unprivileged local users are not described as being able to exploit it.
What does an attacker need to exploit the vulnerability?
The attacker needs local system access and high privileges. The vulnerability involves link resolution before file access and could allow filesystem access.
How can I determine whether remediation is needed?
Check the installed Dell Update Package Framework version. Systems with a version prior to 26.07.03 require updating to address the affected version range.