← Vulnerability feed

Vulnerability record · CVE-2022-26865 · published 26 May 2022

CVE-2022-26865: Dell supportassist os recovery authentication bypass via alternate path vulnerability

Dell · Supportassist Os Recovery

Dell Support Assist OS Recovery versions before 5.5.2 contain an Authentication Bypass vulnerability. An unauthenticated attacker with physical access to the system may exploit this vulnerability by bypassing OS Recovery authentication in order to run arbitrary code on the system as Administrator.

6.8 CVSS 3.1 Medium EPSS 0.30% · top 79.8% CWE-288 · Authentication bypass via alternate pathCWE-287 · Improper authentication
6.8CVSS 3.1 base score, v2 7.2
0.30%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Dell Support Assist OS Recovery versions before 5.5.2 contain an Authentication Bypass vulnerability. An unauthenticated attacker with physical access to the system may exploit this vulnerability by bypassing OS Recovery authentication in order to run arbitrary code on the system as Administrator.

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-26865 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2025-46685Dell supportassist os recovery vulnerabilityDell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissions vulnerability. A low privi…EPSS 0.10%7.8CVE-2025-38747Dell supportassist os recovery vulnerabilityDell SupportAssist OS Recovery, versions prior to 5.5.14.0, contain a Creation of Temporary File With Insecure Permissions vulnerability. A local aut…EPSS 0.15%7.8CVE-2025-22480Dell supportassist os recovery link following vulnerabilityDell SupportAssist OS Recovery versions prior to 5.5.13.1 contain a symbolic link attack vulnerability. A low-privileged attacker with local access c…EPSS 0.18%5.5CVE-2025-46684Dell supportassist os recovery vulnerabilityDell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissions vulnerability. A low privi…EPSS 0.11%5.5CVE-2025-46602Dell supportassist os recovery vulnerabilityDell SupportAssist OS Recovery, versions prior to 5.5.15.0, contain an Insertion of Sensitive Information into Externally-Accessible File or Director…EPSS 0.11%2.4CVE-2025-38746Dell supportassist os recovery information exposure vulnerabilityDell SupportAssist OS Recovery, versions prior to 5.5.14.0, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. An …EPSS 0.18%10.0CVE-2026-20079Cisco Secure Firewall Management Center authentication bypass to rootCisco Secure Firewall Management Center (FMC) Software contains an authentication bypass caused by an improper system process created at boot time. A…KEVEPSS 88%analysed9.3CVE-2026-19490Citrix NetScaler ADC and Gateway authentication bypass via alternate pathNetScaler ADC and NetScaler Gateway contain an authentication bypass via an alternate path or channel (CWE-288). The flaw is remotely reachable witho…KEVEPSS 7.0%analysed

Source: NIST National Vulnerability Database (record CVE-2022-26865), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.