Junglewise Threat Intelligence

CVE-2026-46735: Dell Display and Peripheral Manager Mac OS command injection

CVE-2026-46735 · Severity: high · CVSS 7.8 · Published 2026-06-25

Technologies: Dell Display and Peripheral Manager. Vendors: Dell.

Executive brief

Dell Display and Peripheral Manager for macOS is an application used to manage monitor settings and peripheral devices. A security vulnerability in this software allows a user with low-level access to the computer to execute unauthorized commands. This could lead to a full system compromise, unauthorized data access, or disruption of operations on the affected Mac.

Technical details

An OS command injection vulnerability (CWE-78) exists in Dell Display and Peripheral Manager (DDPM Mac) due to improper neutralization of special elements used in OS commands. The vulnerability can be exploited by a low-privileged attacker with local access to the system. Successful exploitation allows the attacker to execute arbitrary commands with the privileges of the application. The issue is addressed in version 2.3 and later.

Affected products

  • Dell Display and Peripheral Manager (DDPM Mac) prior to 2.3

Timeline

  • 2026-06-11: patched: Remediated version 2.3 released
  • 2026-06-16: advisory: Initial Dell security advisory published
  • 2026-06-25: disclosed: CVE published to NVD dataset

References

Related threats