Sceawere
Vulnerability Detail
CVE-2026-67267UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Dell Command Update Information Disclosure
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.5
- Creation Date
- 2h ago
- Vendor
- Dell
- Product
- Dell Command Update (DCU)
- Attack Type
- CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.5",
"pubDate": "2026-08-19T15:17:51.767Z",
"pubdate": "2026-08-19T15:17:51.767Z",
"executiveSummary": "Dell Command Update (DCU), in versions prior to 5.7.1, suffers from an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability.\nThis security flaw enables a low-privileged local attacker to gain unauthorized access to sensitive system information, leading to information disclosure.\nThe vulnerability affects Dell Command Update systems running software versions earlier than 5.7.1.\nRisk implications include the potential exposure of confidential internal system data that could facilitate further compromise or privilege escalation attempts within the local environment.\nTo successfully execute an attack, the threat actor requires low-privileged local access to the target system.\nNo remote exploitation vectors are indicated, requiring the adversary to have prior local execution capabilities on the host.",
"technicalDetails": "The root cause of the vulnerability stems from improper handling and protection of system data within Dell Command Update, leading to an Exposure of Sensitive System Information to an Unauthorized Control Sphere.\nThe vulnerable component is the Dell Command Update application across affected versions prior to 5.7.1.\nAuthentication requirements involve local user validation, as the exploit vector requires local access to the operating system.\nPrivilege requirements are minimal, needing only low-privileged local access to interact with the vulnerable application or its underlying storage and execution mechanisms.\nNetwork exposure is absent, meaning the vulnerability cannot be exploited remotely over a network interface.\nThe attack flow proceeds as follows: First, a low-privileged adversary establishes local access to a system running an affected version of Dell Command Update. Second, the attacker interacts with the vulnerable component or queries exposed system interfaces lacking proper access controls. Third, the application inadvertently returns or exposes protected internal system data to the unauthorized control sphere. Finally, the attacker captures the sensitive information, resulting in unauthorized information disclosure."
}