Junglewise Threat Intelligence

CVE-2026-86359: Dell Repository Manager incorrect default permissions privilege escalation

CVE-2026-86359 · Severity: high · CVSS 8.5 · Published 2026-09-16

Executive brief

Dell Repository Manager is an administrative tool used to manage and deploy Dell software packages across systems. A flaw in how file permissions are set by default allows an attacker with low-level access to remotely escalate their privileges and gain full control over the system, potentially compromising sensitive data and operations.

Technical details

The vulnerability is an Incorrect Default Permissions issue in Dell Repository Manager versions prior to 3.5.2. A low-privileged attacker with network access can exploit this flaw to achieve privilege escalation, gaining higher-level access to the system. The attack requires low privileges and remote network access (no user interaction needed). An attacker exploiting this can achieve confidentiality, integrity, and availability impacts across system boundaries. The patch is available in version 3.5.2 and later.

Affected products

  • Dell Repository Manager prior to 3.5.2

Timeline

  • 2026-09-16: disclosed
  • 2026-09-16: patched: version 3.5.2 or later

References