Dell Update Package (DUP) Framework, versions 23.12.00 through 24.12.00, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
References
Configurations
History
18 Feb 2026, 19:33
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Dell update Package Framework
Dell |
|
| CPE | cpe:2.3:a:dell:update_package_framework:*:*:*:*:*:*:*:* | |
| Summary |
|
|
| References | () https://www.dell.com/support/kbdoc/en-us/000426781/dsa-2026-081-security-update-for-dell-update-package-dup-framework-vulnerability - Vendor Advisory |
12 Feb 2026, 03:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-12 03:15
Updated : 2026-02-18 19:33
NVD link : CVE-2026-23857
Mitre link : CVE-2026-23857
CVE.ORG link : CVE-2026-23857
JSON object : View
Products Affected
dell
- update_package_framework
CWE
CWE-280
Improper Handling of Insufficient Permissions or Privileges
