← Vulnerability feed

Vulnerability record · CVE-2026-49817 · published 19 August 2026

CVE-2026-49817: Dell command update deserialization of untrusted data vulnerability

Dell · Command Update

Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

7.8 CVSS 3.1 High EPSS 0.31% · top 78.3% CWE-502 · Deserialization of untrusted data
7.8CVSS 3.1 base score
0.31%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
21 Aug 2026Last modified by NVD

Description

Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-49817 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-58565Dell command update missing authorization vulnerabilityDell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could …EPSS 0.14%7.8CVE-2026-58564Dell command update incorrect default permissions vulnerabilityDell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local acce…EPSS 0.14%7.8CVE-2026-53477Dell command update toctou race condition vulnerabilityDell Command Update (DCU), versions prior to 5.7.1, contain a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attac…EPSS 0.12%7.8CVE-2026-49816Dell command update deserialization of untrusted data vulnerabilityDell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local a…EPSS 0.31%7.8CVE-2022-34384Dell alienware update execution with unnecessary privileges vulnerabilityDell SupportAssist Client Consumer (version 3.11.1 and prior), SupportAssist Client Commercial (version 3.2 and prior), Dell Command | Update, Dell U…EPSS 0.23%7.8CVE-2022-34459Dell alienware update improper verification of cryptographic signature vulnerabilityDell Command | Update, Dell Update, and Alienware Update versions prior to 4.7 contain a improper verification of cryptographic signature in get appl…EPSS 0.15%7.8CVE-2022-34382Dell alienware update vulnerabilityDell Command Update, Dell Update and Alienware Update versions prior to 4.6.0 contains a Local Privilege Escalation Vulnerability in the custom catal…EPSS 0.19%7.8CVE-2022-24426Dell alienware update uncontrolled search path element vulnerabilityDell Command | Update, Dell Update, and Alienware Update version 4.4.0 contains a Local Privilege Escalation Vulnerability in the Advanced Driver Res…EPSS 0.24%

Source: NIST National Vulnerability Database (record CVE-2026-49817), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.