Stack-based Buffer Overflow in Dell Update Package Framework
CVE-2026-86358

6.5MEDIUM

Key Information:

Vendor

Dell

Vendor
CVE Published:
16 September 2026

What is CVE-2026-86358?

The Dell Update Package Framework contains a stack-based buffer overflow vulnerability in versions prior to 26.07.03, which can be triggered by an unauthenticated attacker possessing adjacent network access. This flaw could potentially allow the attacker to execute remote code, posing significant security risks to affected systems.

Affected Version(s)

Update Package Framework 0 < 26.07.03 or later

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.