Junglewise Threat Intelligence

CVE-2026-41121: Dell Device Management Agent privilege escalation via link following

CVE-2026-41121 · Severity: high · CVSS 7.3 · Published 2026-07-01

Vendors: Dell.

Executive brief

Dell Device Management Agent, a tool used to manage and configure Dell hardware, contains a security flaw that could allow a user with limited access to gain full administrative control over a system. By manipulating file links, an attacker can trick the software into modifying or accessing files it shouldn't, potentially leading to a complete system compromise. This vulnerability requires the attacker to already have local access to the machine.

Technical details

A link following vulnerability (CWE-59) exists in the Dell Device Management Agent (DDMA) due to improper resolution of file links before access. A local, low-privileged attacker can exploit this by creating symbolic or hard links to sensitive system files, which the agent then interacts with using its higher-level service permissions. Successful exploitation requires some user interaction (UI:R) and leads to a full compromise of confidentiality, integrity, and availability (C:H/I:H/A:H). The issue is resolved in DDMA version 26.05.

Affected products

  • Dell Device Management Agent prior to 26.05

Timeline

  • 2026-06-02: patched: Remediated version 26.05 released.
  • 2026-06-22: advisory: Initial Dell security advisory (DSA-2026-258) published.
  • 2026-07-01: disclosed: CVE-2026-41121 published to the NVD.

References