Junglewise Threat Intelligence

CVE-2026-56795: Dell Server Update Utility DLL search order hijacking

CVE-2026-56795 · Severity: high · CVSS 8.2 · Published 2026-09-17

Vendors: Dell.

Executive brief

Dell Server Update Utility is a system management tool used to update drivers and firmware on Dell servers. Versions before 26.07.01 are vulnerable to DLL search path hijacking, which allows a low-privileged local attacker to execute arbitrary code with elevated privileges by placing a malicious DLL in a location where the application searches for libraries.

Technical details

This vulnerability is an Uncontrolled Search Path Element flaw (CWE-427) in Dell Server Update Utility. The application fails to properly validate or control the search path for dynamic libraries, allowing an attacker to perform DLL hijacking. Exploitation requires local access and low privileges but also requires user interaction (UI:R), and can result in code execution with the application's privileges affecting the system (scope change). The vulnerability affects Windows and Linux versions prior to 26.07.01. A patch is available in version 26.07.01 and later.

Affected products

  • Dell Server Update Utility prior to 26.07.01
  • Dell Driver Pack for Windows prior to 26.07.01
  • Dell Driver Pack for Linux prior to 26.07.01

Timeline

  • 2026-09-17: disclosed
  • 2026-09-17: patched: Version 26.07.01 available

References