CVE-2026-71179: Dell Update Package Framework

High severity, CVSS 7.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

Affected products

  • Dell Update Package Framework: before 26.07.03 (fixed in 26.07.03)

Published 2026-09-16. Last modified 2026-09-21.