Junglewise Threat Intelligence

CVE-2026-49810: Dell Command PowerShell Provider credential logging vulnerability

CVE-2026-49810 · Severity: high · CVSS 7.8 · Published 2026-09-21

Vendors: Dell.

Executive brief

Dell Command PowerShell Provider (DCPP) writes sensitive credentials to PowerShell event logs where local users can access them. An attacker with local access on an affected system could read the logs to steal credentials and compromise the system. The vulnerability affects DCPP versions before 2.10.2.

Technical details

The vulnerability is an insertion of sensitive information into log files (CWE-532) in Dell Command PowerShell Provider. A low-privileged local attacker without user interaction can extract credentials from PowerShell event logs. The attack requires local access and existing user privileges but enables disclosure of confidential authentication material that could lead to privilege escalation or lateral movement.

Affected products

  • Dell Command PowerShell Provider prior to 2.10.2

Timeline

  • 2026-09-21: disclosed
  • 2026-09-17: patched: Version 2.10.2 or later

References