Dell System Update flaw allows attackers to gain root privileges (CVE-2026-86360)

Dell is urging customers to patch a vulnerability (CVE-2026-86360) in Dell System Update (DSU) that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges.

Dell System Update vulnerability CVE-2026-86360

DSU is a tool used by enterprise IT administrators to apply driver, BIOS, and firmware updates to Dell PowerEdge servers.

About CVE-2026-86360

CVE-2026-86360 is a path traversal vulnerability with a CVSS base score of 9.6 that affects DSU versions prior to 2.3.0.0.

“An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. This vulnerability is considered critical because it can be leveraged by an unauthenticated attacker to execute arbitrary code with root privileges,” the company wrote in the advisory.

According to Dell, successful exploitation may lead to complete compromise of the vulnerable application and the underlying operating system.

“Dell recommends customers upgrade at the earliest opportunity,” the company noted, advising users to update to DSU version 2.3.0.0 or later.

Four more vulnerabilities fixed

Dell fixed four other high-severity flaws in DSU. Two of them (CVE-2026-63697 and CVE-2026-71168) could lead to remote execution, and the other two (CVE-2026-86361 and CVE-2026-86362) could let attackers elevate their privileges.

Ori Gabriel reported CVE-2026-86360 and CVE-2026-63697. A researcher using the name saltedfish reported CVE-2026-86361 and CVE-2026-86362, and Nir Yehoshua of Cipher Security Labs reported CVE-2026-71168.

The advisory does not say whether any of the vulnerabilities have been exploited in the wild.

Don't miss