Critical Dell System Update flaw grants root access to enterprise servers

Path traversal vulnerability in command-line deployment tool patched with four other high-severity bugs

By LineZotpaper
Published
Read Time2 min
Dell has warned customers to urgently patch a critical vulnerability in its System Update (DSU) command-line interface, which allows unauthenticated remote attackers to execute arbitrary code with root privileges on PowerEdge enterprise servers. The company also fixed four additional high-severity flaws in the same tool.

The vulnerability, tracked as CVE-2026-86360, is a path traversal weakness in Dell System Update (DSU), a tool used by enterprise IT administrators to deploy BIOS, firmware, and software updates on Linux and Windows systems across PowerEdge server infrastructure. Dell said the flaw could allow an unauthenticated attacker with remote access to gain filesystem access and execute code with root privileges, potentially leading to complete compromise of the vulnerable application and underlying operating system.

Dell has advised customers to update DSU to version 2.3.0.0 or later at the earliest opportunity. The same advisory also patched four high-severity issues: two that could enable remote code execution (CVE-2026-63697 and CVE-2026-71168) and two that could be abused for privilege escalation (CVE-2026-86361 and CVE-2026-86362).

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the FBI have since last year urged software vendors to eliminate path traversal vulnerabilities before shipping, describing such security holes as "unforgivable" since at least 2007.

While Dell has not reported active exploitation of these particular flaws, the company noted that state-backed hacking groups have abused other Dell vulnerabilities in recent years. In February, Mandiant and Google Threat Intelligence Group revealed that suspected Chinese cyber spies (UNC6201) had been exploiting a hardcoded-credential vulnerability in Dell RecoverPoint for Virtual Machines since mid-2024. The North Korean Lazarus group has also exploited a Dell driver bug to deploy rootkits.

§

Analysis

Why This Matters

  • Affects a core enterprise server management tool, giving attackers a pathway to compromise critical infrastructure.
  • Root-level access on PowerEdge systems could allow complete takeover of servers, data exfiltration, or lateral movement within corporate networks.
  • Follows a pattern of state-sponsored groups targeting Dell assets, underscoring supply chain risks in enterprise IT.

Background

Dell System Update is a command-line tool for deploying updates across large fleets of PowerEdge servers, widely used in data centers and corporate environments. Path traversal vulnerabilities are a well-known class of security flaw that CISA and the FBI have singled out as particularly dangerous. Dell has faced scrutiny in recent years over other security issues that were exploited by nation-state actors, including hardcoded credentials and insufficient access controls.

Key Perspectives

Dell Security: Urges immediate patching, calling the vulnerability critical and emphasizing that unauthenticated exploitation is possible. Enterprise IT Administrators: Face a difficult trade-off between patching rapidly to close the window of risk and testing updates in complex environments to avoid operational disruption. Security Researchers and Regulators: Point to recurring path traversal bugs in enterprise tools as an "unforgivable" failure of secure development practices, calling for industry-wide improvements.

What to Watch

  • Whether proof-of-concept code or active exploitation of CVE-2026-86360 emerges in the coming weeks.
  • The speed of patch deployment across enterprise environments as an indicator of organizational risk.
  • Potential for regulatory action or further CISA advisories if path traversal vulnerabilities persist in enterprise software.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.