Junglewise Threat Intelligence

CVE-2026-28262: Dell iDRAC Tools link following vulnerability

CVE-2026-28262 · Severity: medium · CVSS 6 · Published 2026-06-09

Vendors: Dell.

Executive brief

Dell iDRAC Tools, which are used by administrators to manage Dell servers remotely, contain a security flaw that could allow a user with limited access to the system to tamper with sensitive information. An attacker who already has a local account on the machine could exploit this to modify files they should not have access to, potentially disrupting server management operations. This issue requires specific user interaction and local access to be successful.

Technical details

Dell iDRAC Tools versions prior to 11.4.1.0 contain an Improper Link Resolution Before File Access (CWE-59) vulnerability, commonly known as a link following or symlink attack. A low-privileged attacker with local access to the system can exploit this vulnerability by creating symbolic links that the application follows without proper validation. This can lead to unauthorized information tampering or privilege escalation. The exploit requires high complexity (AC:H) and user interaction (UI:R). Dell has released version 11.4.1.0 to remediate this issue.

Affected products

  • Dell iDRAC Tools prior to 11.4.1.0

Timeline

  • 2026-06-08: advisory: Initial release of Dell Security Advisory DSA-2026-239
  • 2026-06-09: disclosed: NVD publication date

References