CVE-2026-49811
8.4Dell · Command | Monitor (DCM)
Dell Command | Monitor (DCM) contains an incorrect permission assignment vulnerability that allows a low privileged local attacker to achieve elevation of privileges.
Executive summary
A high severity privilege escalation vulnerability in Dell Command | Monitor (DCM) allows local attackers to gain unauthorized elevated system access.
Vulnerability
This vulnerability involves an Incorrect Permission Assignment for Critical Resource (CWE-732). A local attacker with low privileges can exploit this flaw to escalate their access level on the host system.
Business impact
The ability for a low privileged user to escalate privileges poses a significant risk to the integrity and confidentiality of the host machine. Given the CVSS score of 8.4, this vulnerability is categorized as high severity because it enables an attacker to bypass standard security boundaries and potentially gain administrative control, which could lead to total system compromise or unauthorized data access.
Remediation
Immediate Action: Update Dell Command | Monitor (DCM) to version 10.13.2 or later to resolve the permission assignment flaw.
Proactive Monitoring: Monitor local system logs for unauthorized attempts to access critical system files or unexpected elevation of user privileges.
Compensating Controls: Restrict local system access to authorized users only and implement the principle of least privilege to minimize the potential impact of local account compromise.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The high severity of this vulnerability necessitates prompt attention. IT administrators should prioritize the deployment of version 10.13.2 across all managed workstations and servers running Dell Command | Monitor to eliminate the risk of privilege escalation. Failure to patch may expose systems to sophisticated local attacks that could result in full administrative compromise.
More Dell CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
Originally found and disclosed by Dell Technologies would like to thank Ori Gabriel for reporting this issue., per the CVE Program record.