CVE-2026-21420

7.3

Dell · Repository Manager

Dell Repository Manager versions prior to 3.4.8 contain an uncontrolled search path element vulnerability that allows local attackers to achieve privilege escalation and arbitrary code execution.

Executive summary

A critical uncontrolled search path element vulnerability in Dell Repository Manager allows local attackers to execute arbitrary code and escalate privileges on affected systems.

Vulnerability

This vulnerability is an uncontrolled search path element (CWE-427) flaw. It requires a low privileged attacker with local access to the system to successfully trigger the exploit.

Business impact

The potential for arbitrary code execution and privilege escalation poses a significant risk to organizational security. Successful exploitation could lead to full system compromise, unauthorized data access, and the potential for lateral movement within the network. Given the CVSS score of 7.3, this high severity vulnerability warrants immediate attention to prevent unauthorized administrative control.

Remediation

Immediate Action: Upgrade to Dell Repository Manager version 3.4.8 or later to remediate the vulnerable search path configuration.

Proactive Monitoring: Review local system access logs for signs of unauthorized privilege escalation attempts or the execution of unexpected binaries by low privileged accounts.

Compensating Controls: Restrict local system access to authorized personnel only and implement robust endpoint security policies to monitor for suspicious process creation or modification of system paths.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The risk associated with this vulnerability is elevated due to the potential for local privilege escalation. Administrators should prioritize patching Dell Repository Manager to version 3.4.8 across all affected environments to eliminate the underlying path control issue and harden the system against local threats.

More Dell CVEs

Sources