Skip to content

Dell System Update CVE-2026-86360: root RCE on PowerEdge

CVE-2026-86360, a CVSS 9.6 path-traversal flaw in Dell System Update, lets an unauthenticated remote attacker run code as root. Fix is DSU 2.3.0.0; four more CVEs patched alongside.

Published 3 min read

Dell has patched CVE-2026-86360, a path-traversal flaw Dell scores 9.6/10 in Dell System Update (DSU), the command-line tool admins use to push BIOS, firmware, and driver updates to PowerEdge servers. Per Dell, the bug lets "an unauthenticated attacker with remote access" obtain filesystem access and execute arbitrary code with root privileges. The fix is in DSU 2.3.0.0. The NVD record is here; Dell's advisory is DSA-2026-324, published October 1.

What's affected

Every DSU build before 2.3.0.0. DSU is a Linux/Windows deployment utility for PowerEdge enterprise infrastructure, so the exposure sits on the management plane — the tooling trusted to patch the fleet — not on an individual workload.

DSA-2026-324 covers five CVEs in total. Alongside the critical path-traversal bug, Dell patched four high-severity flaws:

  • CVE-2026-63697
  • CVE-2026-71168
  • CVE-2026-86361
  • CVE-2026-86362

All five are resolved in the same 2.3.0.0 release, per Dell.

What the bug does

Dell's own language on the critical flaw: "This vulnerability is considered critical because it can be leveraged by an unauthenticated attacker to execute arbitrary code with root privileges. Successful exploitation may allow complete compromise of the vulnerable application and underlying operating system." The path-traversal primitive lets an attacker break out of DSU's expected file paths; root execution follows because the update tool runs privileged.

Exploitation status

No active exploitation has been reported at disclosure, and there is no public proof-of-concept named in Dell's advisory or BleepingComputer's reporting. The 9.6 reflects reachability and impact — unauthenticated, remote, root — not evidence of in-the-wild use. Patch on the merits of the score, not on a threat report that doesn't yet exist.

Action checklist

  1. Check DSU versions across your PowerEdge estate. Anything below 2.3.0.0 is vulnerable.
  2. Upgrade DSU to 2.3.0.0 or later. This single release closes all five CVEs in DSA-2026-324.
  3. Treat DSU hosts as management-plane assets: restrict who and what can reach them on the network while you roll the update.
  4. If DSU is wired into an automated patch pipeline, confirm the pipeline pulls the fixed binary — a stale cached DSU keeps the hole open.

Context

The pattern worth noting is where the flaw lives: not in a workload, but in the update mechanism itself. A root-level RCE in the tool an organization trusts to keep its servers patched inverts the usual threat model — the thing you run to reduce risk becomes the way in. Management-plane and update-tooling CVEs (deployment agents, firmware updaters, out-of-band controllers) deserve the same urgency as an internet-facing app bug, because a foothold there reaches the whole fleet at once.

Related stories