CVE-2026-86360

Published Oct 6, 2026

Last updated 12 hours ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-86360 is a path traversal vulnerability affecting the Dell System Update (DSU) command-line interface (CLI) deployment tool in versions prior to 2.3.0.0. DSU is a utility used by enterprise IT administrators to apply driver, BIOS, and firmware updates to Dell PowerEdge servers. The vulnerability stems from an improper limitation of a pathname to a restricted directory, which can allow an unauthenticated remote attacker to gain unauthorized access to the system's filesystem. By leveraging this filesystem access, an unauthenticated remote attacker can execute arbitrary code with root privileges on the affected system. This can result in unauthorized control over the DSU application and the underlying operating system. To remediate the vulnerability, Dell has released a patch and advises administrators to upgrade to DSU version 2.3.0.0 or later.

Description
Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. This vulnerability is considered critical because it can be leveraged by an unauthenticated attacker to execute arbitrary code with root privileges. Successful exploitation may allow complete compromise of the vulnerable application and underlying operating system. Dell recommends customers upgrade at the earliest opportunity.
Source
security_alert@emc.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.6
Impact score
6
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

security_alert@emc.com
CWE-22

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

7

  1. 🚨 DELL SYSTEM UPDATE FLAW COULD GIVE UNAUTHENTICATED ATTACKERS ROOT (CVE-2026-86360, CVSS 9.6) Dell security advisory DSA-2026-324 fixes a critical path traversal vulnerability in Dell System Update (DSU). Dell says an unauthenticated remote attacker could leverage it to http

    @DailyDarkWeb

    7 Oct 2026

    3062 Impressions

    2 Retweets

    11 Likes

    4 Bookmarks

    2 Replies

    0 Quotes

  2. Dell pide parchar ya CVE-2026-86360 (CVSS 9.6) en Dell System Update: un atacante remoto sin autenticación puede abusar de un path traversal y ejecutar código como root en servidores PowerEdge. No hay explotación reportada, pero es la herramienta que mueve BIOS y firmware.

    @jfernandogg

    6 Oct 2026

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Dell System Update flaw allows attackers to gain root privileges (CVE-2026-86360) www.​helpnetsecurity.​com/2026/10/06/dell-system-update-vulnerability-cve-2026-86360/ https://t.co/lXkOx9lwB5

    @TheCyberSecHub

    6 Oct 2026

    777 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Dell System Update flaw allows attackers to gain root privileges (CVE-2026-86360): Dell is urging customers to patch a vulnerability (CVE-2026-86360) in Dell System Update (DSU) that could… www.​helpnetsecurity.​com/2026/10/06/dell-system-update-vulnerability-cve-2026-86360

    @shah_sheikh

    6 Oct 2026

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Rejetto HFS CVE-2026-61500 (CVSS 9.3) is being targeted: forged admin sessions lead to RCE. Upgrade to 3.2.1+. Also: out-of-band Exchange fix (CVE-2026-96940) and a critical Dell System Update bug (CVE-2026-86360). https://t.co/QvcNCpqRbz #infosec #CVE

    @tpsecuritymdr

    5 Oct 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🚨 CRITICAL: Dell System Update flaw CVE-2026-86360 carries a CVSS 9.6 and could allow attackers to execute code with root privileges. Dell patched five vulnerabilities in Dell System Update (DSU), including CVE-2026-86360, CVE-2026-86361, CVE-2026-86362, CVE-2026-63697 and

    @ThreatWire_

    2 Oct 2026

    1613 Impressions

    1 Retweet

    6 Likes

    5 Bookmarks

    0 Replies

    1 Quote