Junglewise Threat Intelligence

CVE-2026-35159: Dell Client Platform BIOS authentication bypass

CVE-2026-35159 · Severity: medium · CVSS 5.3 · Published 2026-07-03

Vendors: Dell.

Executive brief

A security vulnerability exists in the BIOS of various Dell laptops and desktops, including Alienware, Inspiron, and G-series models. The BIOS is the fundamental software that starts a computer before the operating system loads. An attacker with physical access to the device could bypass security checks, potentially leading to the unauthorized disclosure of sensitive information or compromise of the system's integrity.

Technical details

Dell Client Platform BIOS is affected by an authentication bypass vulnerability (CWE-305: Authentication Bypass by Primary Weakness). The flaw allows an unauthenticated attacker with physical access to the target device to bypass intended authentication mechanisms. Successful exploitation requires high complexity and could lead to information disclosure, as well as unauthorized modification of system settings. Dell has released BIOS updates for a wide range of affected models, including Alienware, Inspiron, Vostro, and G-series platforms, to remediate this issue.

Affected products

  • Dell Inspiron 15 3520 prior to 1.41.0
  • Dell G15 5530 prior to 1.33.0
  • Dell Alienware 16 Area-51 AA16250 prior to 2.4.1
  • Dell Alienware 16 Aurora AC16250 prior to 1.13.0
  • Dell Alienware 16X Aurora AC16251 prior to 2.4.0
  • Dell Alienware 18 Area-51 AA18250 prior to 2.4.1
  • Dell Alienware Area-51 AAT2250 prior to 1.17.2
  • Dell Alienware Aurora ACT1250 prior to 1.16.2
  • Dell Alienware m15 R6/R7 prior to 1.44.0 (R6), prior to 1.40.0 (R7)
  • Dell Alienware m16 R1/R2 prior to 1.34.0 (R1), prior to 1.21.0 (R2)
  • Dell Alienware m18 R1/R2 prior to 1.34.0 (R1), prior to 1.22.0 (R2)
  • Dell Alienware x14 R2 / x16 R1 / x16 R2 prior to 1.32.0 (x14 R2/x16 R1), prior to 1.22.0 (x16 R2)
  • Dell ChengMing 3900 / 3910 / 3911 prior to 1.40.0 (3900), prior to 1.36.0 (3910/3911)
  • Dell G15 5510 / 5511 / 5520 prior to 1.40.0 (5510), prior to 1.43.0 (5511), prior to 1.41.0 (5520)
  • Dell G16 7620 / 7630 prior to 1.41.0 (7620), prior to 1.33.0 (7630)

Timeline

  • 2026-06-08: patched: Initial batch of remediated BIOS versions released for several models.
  • 2026-07-03: advisory: NVD and Dell published the vulnerability details.

References