Dell System Update Flaw Grants Root Privileges on PowerEdge Servers
A critical path traversal vulnerability in Dell System Update (DSU) versions prior to 2.3.0.0 allows unauthenticated remote attackers to gain root privileges on PowerEdge servers.

Dell has issued an urgent warning to its customers regarding a critical vulnerability, identified as CVE-2026-86360, present in its Dell System Update (DSU) software. This flaw, if exploited, could allow an unauthenticated attacker with remote access to execute arbitrary code with root privileges on affected Dell PowerEdge servers. The severity of this vulnerability is underscored by its CVSS base score of 9.6, placing it in the critical category.
Dell System Update is a crucial tool for enterprise IT administrators, designed to streamline the deployment of driver, BIOS, and firmware updates to Dell PowerEdge server infrastructure. Its function makes it a prime target for attackers seeking to gain deep access to critical server hardware. The path traversal nature of CVE-2026-86360 means that an attacker could manipulate file paths to access or overwrite system files, ultimately leading to the execution of malicious code with the highest level of system privileges.
The advisory explicitly states that successful exploitation of this vulnerability could result in the complete compromise of the affected application and the underlying operating system. This level of access would enable an attacker to install malware, exfiltrate sensitive data, disrupt operations, or use the compromised server as a pivot point for further network intrusions. Given the critical nature of PowerEdge servers in enterprise environments, the potential impact is significant.
Dell strongly recommends that all customers upgrade their Dell System Update software to version 2.3.0.0 or later as soon as possible to mitigate this risk. Prompt patching is essential to prevent potential exploitation and maintain the security posture of their server infrastructure. The company's proactive advisory aims to ensure customers are aware of the threat and take immediate action.
In addition to the critical CVE-2026-86360, Dell also addressed four other high-severity vulnerabilities within DSU. Two of these, CVE-2026-63697 and CVE-2026-71168, could also lead to remote code execution. The remaining two, CVE-2026-86361 and CVE-2026-86362, are privilege escalation flaws. These additional vulnerabilities further emphasize the importance of updating DSU to the latest version to ensure comprehensive protection.
The vulnerabilities were reported by several security researchers. Ori Gabriel is credited with discovering CVE-2026-86360 and CVE-2026-63697. Additionally, a researcher known as saltedfish reported CVE-2026-86361 and CVE-2026-86362, while Nir Yehoshua of Cipher Security Labs identified CVE-2026-71168. The advisory did not indicate whether any of these vulnerabilities have been actively exploited in the wild, but the high CVSS scores suggest a strong potential for exploitation.
This incident highlights the ongoing risks associated with system management tools, which often possess high levels of access. Organizations must maintain vigilance in patching these tools and ensure their configurations are secure to prevent attackers from leveraging them for widespread compromise. The prompt disclosure and patching by Dell are crucial steps in protecting their customer base from this critical threat.
This new report details four additional vulnerabilities within Dell System Update (DSU), including two privilege escalation flaws (CVE-2026-86361, CVE-2026-86362) with CVSS scores of 8.2, and two other path traversal and improper certificate validation issues (CVE-2026-71168, CVE-2026-63697) with scores of 7.3 and 7.6 respectively. The critical path traversal vulnerability CVE-2026-86360, previously reported, is also elaborated upon, noting that its exploitation requires user interaction despite its high CVSS score of 9.6.