CVE-2026-81469

7.8

Dell · Inventory Collector Client

Dell Inventory Collector Client versions prior to 15.0.0 are vulnerable to an unquoted search path flaw, which may allow low privileged local attackers to achieve code execution and privilege escalation.

Executive summary

A high-severity unquoted search path vulnerability in Dell Inventory Collector Client versions prior to 15.0.0 enables local attackers to achieve code execution and elevate privileges.

Vulnerability

This vulnerability involves an unquoted search path (CWE-428) in the Dell Inventory Collector Client. A low privileged authenticated user with local access can exploit this flaw to execute arbitrary code with elevated permissions.

Business impact

The potential for privilege escalation and arbitrary code execution poses a significant risk to system integrity and confidentiality. Given the CVSS score of 7.8, this vulnerability is classified as high severity, as it allows a local attacker to bypass security controls and gain full control over the affected workstation or server.

Remediation

Immediate Action: Update the Dell Inventory Collector Client to version 15.0.0 or later to resolve the unquoted search path vulnerability.

Proactive Monitoring: Monitor local system logs for unauthorized service execution or unexpected process spawning associated with the Inventory Collector Client.

Compensating Controls: Ensure that local user permissions are strictly enforced and minimize the number of users with local interactive access to critical infrastructure systems.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Organizations should prioritize the deployment of the 15.0.0 patch for all instances of the Dell Inventory Collector Client. Due to the high-severity nature of the flaw and the risk of local privilege escalation, remediation should be integrated into the next available maintenance cycle to minimize the attack surface on local hosts.

More Dell CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section