CVE-2026-26034
7.8Dell Inc. · UPS Multi-UPS Management Console (MUMC)
A vulnerability in Dell UPS Multi-UPS Management Console (MUMC) allows for arbitrary code execution via a specially crafted DLL due to incorrect default permissions.
Executive summary
A critical vulnerability in Dell UPS Multi-UPS Management Console (MUMC) could allow a local attacker to execute arbitrary code with SYSTEM privileges.
Vulnerability
This flaw is classified as Incorrect Default Permissions (CWE-276), which enables an attacker to perform DLL hijacking. The vulnerability requires local access and user interaction to execute malicious code with high SYSTEM privileges.
Business impact
Successful exploitation allows an attacker to gain full control over the host system, potentially leading to total system compromise and lateral movement within the network. With a CVSS score of 7.8, this vulnerability represents a high risk to business continuity and infrastructure integrity, as it grants the attacker elevated SYSTEM-level permissions.
Remediation
Immediate Action: Update the affected Dell UPS Multi-UPS Management Console software to the version specified in the Dell security advisory at https://www.dell.com/support/home/en-us/drivers/driversdetails?driverid=038h3.
Proactive Monitoring: Review system logs for unexpected file creation or service installation events, particularly those involving DLL files within the application directory.
Compensating Controls: Ensure that the host operating system is hardened with appropriate file system permissions to prevent unauthorized users from writing to application directories, which restricts the potential for DLL injection.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high level of privileges an attacker can obtain, administrators must prioritize the application of the vendor-supplied patch. Ensure that all systems running the affected version are identified and updated immediately to prevent potential local privilege escalation and subsequent system compromise.