Exposure of Sensitive System Information in Dell Command Update
CVE-2026-67267
5.5MEDIUM
What is CVE-2026-67267?
Dell Command Update (DCU) versions prior to 5.7.1 are vulnerable to exposure of sensitive system information to an unauthorized control sphere. Low privileged attackers with local access can potentially exploit this vulnerability, which may lead to unauthorized information disclosure. It is crucial for users to update to the latest version to mitigate risks associated with this security flaw.
Affected Version(s)
Dell Command Update (DCU) 0 < 5.7.1
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dell would like to thank Ori Gabriel for reporting this issue.