{"id":"CVE-2026-56795","title":"Dell Server Update Utility, versions prior to 26.07.01, contains an Uncontrolled Search Path Element vulnerability","summary":"Dell Server Update Utility, versions prior to 26.07.01, contains an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.","severity":"high","cvss":8.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H","cwe":["CWE-427"],"vendor":"Dell","product":"Driver Pack For Windows OS","affected":["driver_pack_for_windows_os < 26.07.01","driver_pack_for_linux_os < 26.07.01","server_update_utility_windows_64-bit_format < 26.07.01","server_update_utility_linux_64-bit_format < 26.07.01"],"published":"2026-09-17","updated":"2026-09-19","sourceUpdated":"2026-09-19T15:16:59.640","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-56795","references":[{"url":"https://www.dell.com/support/kbdoc/en-us/000509930/dsa-2026-422-security-update-for-dell-server-update-utility-suu-vulnerability","label":"security_alert@emc.com"}],"tags":["nvd","cve.org"],"epss":0.00128,"epssPercentile":0.0279,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-19T13:45:30.538404Z"},"ingestedAt":"2026-09-17T16:21:47.708Z","slug":"CVE-2026-56795","body":"## Overview\n\nDell Server Update Utility, versions prior to 26.07.01, contains an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":45.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}