Sceawere

Vulnerability Detail

CVE-2026-67267UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Dell Command Update Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
2h ago
Vendor
Dell
Product
Dell Command Update (DCU)
Attack Type
CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-08-19T15:17:51.767Z",
  "pubdate": "2026-08-19T15:17:51.767Z",
  "executiveSummary": "Dell Command Update (DCU), in versions prior to 5.7.1, suffers from an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability.\nThis security flaw enables a low-privileged local attacker to gain unauthorized access to sensitive system information, leading to information disclosure.\nThe vulnerability affects Dell Command Update systems running software versions earlier than 5.7.1.\nRisk implications include the potential exposure of confidential internal system data that could facilitate further compromise or privilege escalation attempts within the local environment.\nTo successfully execute an attack, the threat actor requires low-privileged local access to the target system.\nNo remote exploitation vectors are indicated, requiring the adversary to have prior local execution capabilities on the host.",
  "technicalDetails": "The root cause of the vulnerability stems from improper handling and protection of system data within Dell Command Update, leading to an Exposure of Sensitive System Information to an Unauthorized Control Sphere.\nThe vulnerable component is the Dell Command Update application across affected versions prior to 5.7.1.\nAuthentication requirements involve local user validation, as the exploit vector requires local access to the operating system.\nPrivilege requirements are minimal, needing only low-privileged local access to interact with the vulnerable application or its underlying storage and execution mechanisms.\nNetwork exposure is absent, meaning the vulnerability cannot be exploited remotely over a network interface.\nThe attack flow proceeds as follows: First, a low-privileged adversary establishes local access to a system running an affected version of Dell Command Update. Second, the attacker interacts with the vulnerable component or queries exposed system interfaces lacking proper access controls. Third, the application inadvertently returns or exposes protected internal system data to the unauthorized control sphere. Finally, the attacker captures the sensitive information, resulting in unauthorized information disclosure."
}
CVE-2026-67267: Dell Command Update Information Disclosure (MEDIUM Severity, CVSS: 5.5) - Sceawere