Deserialization of Untrusted Data Vulnerability in Dell Command Update
CVE-2026-49816
7.8HIGH
What is CVE-2026-49816?
The Dell Command Update software, prior to version 5.7.1, exposes a vulnerability related to the deserialization of untrusted data. This flaw may allow a local attacker with limited privileges to exploit the software, potentially leading to an elevation of privileges. Users of affected versions are urged to upgrade to the latest version to mitigate risks associated with this vulnerability.
Affected Version(s)
Dell Command Update (DCU) 0 < 5.7.1
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dell would like to thank PRL for reporting this issue.