Critical Dell System Update Tool Vulnerability Allows Attackers to Execute Code as Root User

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Dell has released security updates for five vulnerabilities in Dell System Update (DSU), including a critical flaw that could let an unauthenticated remote attacker execute code with root privileges. The issues affect versions before 2.3.0.0, and Dell urges customers to upgrade at the earliest opportunity.

The company published security advisory DSA-2026-324 on October 1, 2026. DSU is a command-line tool that helps administrators deploy BIOS, firmware, and software updates across Dell PowerEdge servers running Linux and Windows, making its security important for enterprise server management.

Critical Path Traversal Vulnerability

The most serious issue, CVE-2026-86360, carries a CVSS score of 9.6. Dell identifies it as a path traversal vulnerability, meaning the tool fails to keep file access within an intended directory. An attacker with remote access could exploit the weakness without first signing in to the affected system.

Dell warns that exploitation could provide filesystem access and allow arbitrary code execution with root privileges. Successful attacks could completely compromise both DSU and the underlying operating system. However, the published CVSS vector lists user interaction as required, an important detail that distinguishes unauthenticated access from an attack requiring no user involvement.

Dell credits researcher Ori Gabriel with reporting this critical flaw and the separate certificate validation issue. The advisory does not describe the exact user action required, vulnerable file paths, or a complete attack sequence. These limits matter: the warning establishes serious risk, but does not provide enough detail to reconstruct an exploit.

Four Additional Security Flaws

Two further vulnerabilities could allow local users with limited permissions to gain higher privileges. CVE-2026-86361 involves incorrect permissions assigned to a critical resource, while CVE-2026-86362 stems from improper access control. Both carry CVSS scores of 8.2 and require local access, unlike the critical remote path traversal flaw.

CVE-2026-63697, rated 7.6, involves improper certificate validation. Dell says a remote attacker who already holds high privileges could exploit it to achieve remote execution. CVE-2026-71168, rated 7.3, is another path traversal flaw. Its stated prerequisite is local access with low privileges, although Dell describes its potential outcome as remote execution.

Dell lists DSU version 2.3.0.0 or later as the fix for all five vulnerabilities. Administrators should identify installations below that version and obtain the corrected release through the official Dell download linked in the advisory. Installing an earlier DSU release does not meet Dell’s stated remediation requirement.

The disclosure follows separate critical Dell Container Storage vulnerabilities covered by Cyber Security News, highlighting another update priority for Dell environments. Those flaws affect a different product and need separate remediation. Dell had not flagged the DSU flaws as actively exploited in reporting published October 5, but customers should not delay patching.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

The post Critical Dell System Update Tool Vulnerability Allows Attackers to Execute Code as Root User appeared first on Cyber Security News.