Published on October 6, 2026
Critical Dell System Update Tool Vulnerability Allows Attackers to Execute Code as Root User
Severity
Critical
Detail
Dell has released security updates addressing five vulnerabilities affecting Dell System Update (DSU), including a critical vulnerability that could allow attackers to execute arbitrary code with root privileges. The vulnerabilities affect Dell System Update versions prior to 2.3.0.0, and customers are advised to upgrade as soon as possible.
The most severe vulnerability, CVE-2026-86360, is a path traversal vulnerability. According to Dell, a remote attacker could exploit the flaw to gain unauthorized filesystem access and execute arbitrary code with root privileges, potentially leading to complete compromise of the affected system.
In addition to the critical vulnerability, four other flaws were disclosed. CVE-2026-86361 and CVE-2026-86362 could allow local attackers with limited privileges to elevate their permissions. CVE-2026-63697 is an improper certificate validation vulnerability that may allow remote code execution under specific conditions, while CVE-2026-71168 is another path traversal vulnerability that could lead to further compromise of affected systems.
Dell stated that version 2.3.0.0 addresses all five vulnerabilities and noted that there is no indication of active exploitation at the time of disclosure.
| CVE ID | Summary | Severity |
| CVE-2026-86360 | Path traversal vulnerability that could allow remote code execution with root privileges. | 9.6 (Critical) |
| CVE-2026-86361 | Incorrect permissions vulnerability that could allow local privilege escalation. | 8.2 (High) |
| CVE-2026-86362 | Improper access control vulnerability that could allow local privilege escalation. | 8.2 (High) |
| CVE-2026-63697 | Improper certificate validation vulnerability that could lead to remote code execution. | 7.6 (High) |
| CVE-2026-71168 | Path traversal vulnerability could result in further system compromise. | 7.3 (High) |
Affected Products
The following product is affected:
- Dell System Update (DSU) versions earlier than 2.3.0.0
Recommendation
Organizations should implement the following measures:
- Upgrade Dell System Update to version 2.3.0.0 or later immediately.
- Identify servers and endpoints running vulnerable DSU versions.
- Review privileged account activity and system logs for indications of unauthorized access or privilege escalation.
- Restrict access to management interfaces and update infrastructure to trusted administrative users only.
- Ensure that firmware and software updates are obtained exclusively from official Dell sources.
- Incorporate DSU updates into regular vulnerability management and patching processes.
Source
https://cybersecuritynews.com/dell-system-update-tool-vulnerability/
