CVE-2026-56795 PUBLISHED

Assigner: dell
Reserved: 23.06.2026 Published: 17.09.2026 Updated: 17.09.2026

Dell Server Update Utility, versions prior to 26.07.01, contains an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
CVSS Score: 8.2

Product Status

Vendor Dell
Product Driver Pack For Windows OS
Versions Default: unaffected
  • affected from 0 to 26.07.01 (excl.)
Vendor Dell
Product Driver Pack For Linux OS
Versions Default: unaffected
  • affected from 0 to 26.07.01 (excl.)
Vendor Dell
Product Server Update Utility, Windows 64-bit format
Versions Default: unaffected
  • affected from 0 to 26.07.01 (excl.)
Vendor Dell
Product Server Update Utility, Linux 64-bit format
Versions Default: unaffected
  • affected from 0 to 26.07.01 (excl.)

References

Problem Types

  • CWE-427: Uncontrolled Search Path Element CWE