CVE-2026-23857

Dell Update Package (DUP) Framework, versions 23.12.00 through 24.12.00, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dell:update_package_framework:*:*:*:*:*:*:*:*

History

18 Feb 2026, 19:33

Type Values Removed Values Added
First Time Dell update Package Framework
Dell
CPE cpe:2.3:a:dell:update_package_framework:*:*:*:*:*:*:*:*
Summary
  • (es) El Framework de Dell Update Package (DUP), versiones 23.12.00 a 24.12.00, contiene una vulnerabilidad de manejo inadecuado de permisos o privilegios insuficientes. Un atacante con privilegios bajos con acceso local podría potencialmente explotar esta vulnerabilidad, lo que lleva a una elevación de privilegios.
References () https://www.dell.com/support/kbdoc/en-us/000426781/dsa-2026-081-security-update-for-dell-update-package-dup-framework-vulnerability - () https://www.dell.com/support/kbdoc/en-us/000426781/dsa-2026-081-security-update-for-dell-update-package-dup-framework-vulnerability - Vendor Advisory

12 Feb 2026, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-12 03:15

Updated : 2026-02-18 19:33


NVD link : CVE-2026-23857

Mitre link : CVE-2026-23857

CVE.ORG link : CVE-2026-23857


JSON object : View

Products Affected

dell

  • update_package_framework
CWE
CWE-280

Improper Handling of Insufficient Permissions or Privileges