Dell has patched a critical path traversal flaw, CVE-2026-86360, in the command-line interface of Dell System Update (DSU) that lets unauthenticated remote attackers execute code with root privileges. The same advisory fixes four more vulnerabilities, and all are resolved in DSU 2.3.0.0 or later.
CVE-2026-86360 in the Dell System Update Command-Line Interface
Dell published its advisory on October 5. The headline flaw, CVE-2026-86360, is a critical path traversal in the DSU command-line interface. According to Dell, an unauthenticated attacker with remote access could potentially gain filesystem access, and the flaw allows code execution with root privileges.
Dell System Update is the utility used to apply Dell updates, and the vulnerable component is its command-line interface. The source report does not give a CVSS score for the flaw.
Root-Level Code Execution Without Authentication
Two properties make CVE-2026-86360 the most serious item in the advisory. The attacker does not need to authenticate, and successful exploitation yields root privileges, the highest level of access on the system. Systems running a vulnerable version of DSU therefore face root-level code execution from a remote, unauthenticated position.
Four Additional Flaws in the Same Advisory
The advisory also covers four further vulnerabilities, two of them remote code execution bugs and two privilege escalation bugs.
CVE-2026-63697 and CVE-2026-71168: High-Severity Remote Code Execution
CVE-2026-63697 and CVE-2026-71168 are both rated high severity and both allow remote code execution. Dell fixed them in the same release as the critical flaw.
CVE-2026-86361 and CVE-2026-86362: Privilege Escalation
CVE-2026-86361 and CVE-2026-86362 are privilege escalation flaws. Together with the two remote code execution bugs and the critical path traversal, they make up five vulnerabilities addressed by the advisory.
Fixed Version and Exploitation Status
All five vulnerabilities are fixed in DSU 2.3.0.0 or later. Dell’s remediation guidance is to update to that version or a newer one.
No active exploitation had been reported at the time of publication. The absence of reported exploitation applies to the point the advisory and the report on it were published, and it does not describe what attackers may do later.
What Root Access Through DSU Would Give an Attacker
Root privileges give an attacker complete control over a system, including the ability to read and change any file, install software and alter security settings. Because DSU is a system update tool installed on Dell machines, a flaw in its command-line interface places that level of control within reach of a remote attacker who can reach the vulnerable component.
The path traversal at the center of CVE-2026-86360 is the mechanism that provides the filesystem access Dell describes. A path traversal flaw lets an attacker reach files and directories outside the location a program intends to expose.
Scope of the Advisory
The advisory is limited to one Dell utility. Dell describes the filesystem access an unauthenticated remote attacker could gain as a potential outcome, and it lists no workaround in the source report.
Dell’s advisory covers a single product, the Dell System Update command-line interface, and a single fixed release line. The five CVE identifiers, CVE-2026-86360, CVE-2026-63697, CVE-2026-71168, CVE-2026-86361 and CVE-2026-86362, are all resolved by the same update.
No exploitation of these flaws had been reported when the advisory was published. Administrators of Dell systems that run the DSU command-line interface can compare their installed version against the 2.3.0.0 fixed release to see whether all five flaws apply to them.
Dell published the advisory on October 5, and the reporting on it did not include a CVSS score for CVE-2026-86360 or for the four other flaws. The severity labels in the advisory are the only ratings available to readers of the report, and they are: critical for the path traversal, and high for the two remote code execution bugs.
