Junglewise Threat Intelligence

CVE-2026-82164: Dell Trusted Device Client incorrect permission assignment

CVE-2026-82164 · Severity: high · CVSS 7.1 · Published 2026-09-24

Vendors: Dell.

Executive brief

Dell Trusted Device Client, used to manage device authentication and security on enterprise systems, contains a flaw in file permissions that allows unprivileged local users to read and modify sensitive system data. An attacker with local access could exploit this to tamper with critical information, potentially compromising system integrity and confidentiality.

Technical details

The vulnerability stems from improper permission assignment on a critical resource in Dell Trusted Device Client versions prior to 8.1.359.0. A low-privileged attacker with local access can exploit this without user interaction to achieve both information disclosure and tampering capabilities. The flaw is resolved in version 8.1.359.0 and later.

Affected products

  • Dell Trusted Device Client prior to 8.1.359.0

Timeline

  • 2026-09-24: disclosed
  • 2026-09-23: patched: Version 8.1.359.0 or later

References