Dell: Critical Dell System Update Tool Vulnerability Allows Attackers to Execute Code as Root User

Dell: Critical Dell System Update Tool Vulnerability Allows Attackers to Execute Code as Root User

Dell Patches Critical Flaws in System Update Tool, Including Remote Code Execution Risk

Dell has released security updates addressing five vulnerabilities in Dell System Update (DSU), a command-line tool used to deploy BIOS, firmware, and software updates across Dell PowerEdge servers running Linux and Windows. The most severe flaw, CVE-2026-86360 (CVSS 9.6), is a path traversal vulnerability that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges. Exploitation requires user interaction, though Dell has not disclosed specific attack details.

The vulnerabilities affect DSU versions prior to 2.3.0.0, and Dell advises administrators to upgrade immediately. The advisory (DSA-2026-324), published on October 1, 2026, highlights the following additional flaws:

  • CVE-2026-86361 (CVSS 8.2) – Local privilege escalation due to incorrect permissions.
  • CVE-2026-86362 (CVSS 8.2) – Local privilege escalation from improper access control.
  • CVE-2026-63697 (CVSS 7.6) – Remote code execution via improper certificate validation (requires high privileges).
  • CVE-2026-71168 (CVSS 7.3) – Local path traversal leading to remote execution (low-privilege access required).

The critical flaw (CVE-2026-86360) was reported by researcher Ori Gabriel, who also identified the certificate validation issue. While Dell has not confirmed active exploitation, the severity of the vulnerabilities particularly the remote code execution risk underscores the urgency of patching.

Administrators should verify DSU installations and upgrade to version 2.3.0.0 or later via Dell’s official download. The advisory follows recent disclosures of separate critical vulnerabilities in Dell Container Storage, reinforcing the need for comprehensive patch management in Dell environments.

Source: https://cybersecuritynews.com/dell-system-update-tool-vulnerability/

Dell Technologies cybersecurity rating report: https://www.rankiteo.com/company/delltechnologies

"id": "DEL1791296800",
"linkid": "delltechnologies",
"type": "Vulnerability",
"date": "10/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Technology/Hardware',
                        'name': 'Dell',
                        'type': 'Corporation'}],
 'attack_vector': 'Remote',
 'customer_advisories': 'Upgrade to DSU version 2.3.0.0 or later',
 'date_publicly_disclosed': '2026-10-01',
 'description': 'Dell has released security updates addressing five '
                'vulnerabilities in Dell System Update (DSU), a command-line '
                'tool used to deploy BIOS, firmware, and software updates '
                'across Dell PowerEdge servers running Linux and Windows. The '
                'most severe flaw, CVE-2026-86360 (CVSS 9.6), is a path '
                'traversal vulnerability that could allow an unauthenticated '
                'remote attacker to execute arbitrary code with root '
                'privileges. Exploitation requires user interaction, though '
                'Dell has not disclosed specific attack details.',
 'impact': {'operational_impact': 'Potential unauthorized code execution with '
                                  'root privileges',
            'systems_affected': 'Dell PowerEdge servers running Linux and '
                                'Windows with DSU versions prior to 2.3.0.0'},
 'post_incident_analysis': {'corrective_actions': 'Patch vulnerabilities by '
                                                  'upgrading to DSU version '
                                                  '2.3.0.0 or later',
                            'root_causes': 'Path traversal vulnerability '
                                           '(CVE-2026-86360), incorrect '
                                           'permissions (CVE-2026-86361), '
                                           'improper access control '
                                           '(CVE-2026-86362), improper '
                                           'certificate validation '
                                           '(CVE-2026-63697), local path '
                                           'traversal (CVE-2026-71168)'},
 'recommendations': 'Administrators should verify DSU installations and '
                    'upgrade to version 2.3.0.0 or later via Dell’s official '
                    'download. Comprehensive patch management is advised.',
 'references': [{'source': 'Dell Advisory DSA-2026-324'}],
 'response': {'communication_strategy': 'Public advisory (DSA-2026-324)',
              'containment_measures': 'Upgrade to DSU version 2.3.0.0 or later',
              'remediation_measures': 'Patch management and verification of '
                                      'DSU installations'},
 'title': 'Dell Patches Critical Flaws in System Update Tool, Including Remote '
          'Code Execution Risk',
 'type': 'Vulnerability',
 'vulnerability_exploited': ['CVE-2026-86360',
                             'CVE-2026-86361',
                             'CVE-2026-86362',
                             'CVE-2026-63697',
                             'CVE-2026-71168']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.