Junglewise Threat Intelligence

CVE-2026-32658: Dell Automation Platform privilege escalation via missing authorization

CVE-2026-32658 · Severity: high · CVSS 8 · Published 2026-05-11

Vendors: Dell.

Executive brief

Dell Automation Platform, a tool used for orchestrating and automating IT workflows, contains a security flaw that could allow a user with limited access to gain higher-level administrative permissions. If exploited, an attacker could potentially take control of the platform, access sensitive configuration data, or disrupt automated business operations. Organizations should upgrade to version 2.0.0.0 or later to resolve this issue.

Technical details

A missing authorization vulnerability (CWE-862) exists in Dell Automation Platform versions prior to 2.0.0.0. The flaw allows a remote attacker with low-level authenticated access to bypass intended permission checks. According to the CVSS vector, the attack requires some user interaction (UI:R) but can result in a high impact on confidentiality, integrity, and availability. Successful exploitation leads to elevation of privileges, potentially granting the attacker administrative control over the platform. The issue is remediated in version 2.0.0.0 and later.

Affected products

  • Dell Automation Platform Versions prior to 2.0.0.0

Timeline

  • 2026-04-27: disclosed: Initial release of Dell Security Advisory DSA-2026-193
  • 2026-05-11: advisory: NVD publication date

References