Vulnerability Details CVE-2026-67268
Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges and Server-side request forgery.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 1.1%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2026-67268
-
cpe:2.3:a:dell:command_update:-
-
cpe:2.3:a:dell:command_update:3.1
-
cpe:2.3:a:dell:command_update:4.4.0
-
cpe:2.3:a:dell:command_update:4.5.0
-
cpe:2.3:a:dell:command_update:4.6.0
-
cpe:2.3:a:dell:command_update:4.7.1
-
cpe:2.3:a:dell:command_update:4.8.0
-
cpe:2.3:a:dell:command_update:4.9.0
-
cpe:2.3:a:dell:command_update:5.0
-
cpe:2.3:a:dell:command_update:5.1
-
cpe:2.3:a:dell:command_update:5.2
-
cpe:2.3:a:dell:command_update:5.3
-
cpe:2.3:a:dell:command_update:5.4
-
cpe:2.3:a:dell:command_update:5.5
-
cpe:2.3:a:dell:command_update:5.6
-
cpe:2.3:a:dell:command_update:5.7