Critical Dell DSU Flaw Let Unauthenticated Attackers Execute Code with Root Privileges

The CVSS 9.6 path traversal flaw in the DSU tool enabled unauthenticated remote code execution; Dell fixed four additional vulnerabilities in the same release.

Published on Oct 6, 2026
Alex Blake Written by Alex Blake
Critical Dell DSU Flaw Let Unauthenticated Attackers Execute Code with Root Privileges

Dell has alerted users that a critical flaw in its Dell System Update (DSU) tool could let an attacker gain root access to a victim’s machine, potentially giving them complete compromise of the vulnerable application and underlying operating system. The company has urged affected customers to update as soon as possible.

The vulnerability is tracked as CVE-2026-86360 and has a CVSS score of 9.6, placing it within the “Critical” category. The flaw affects unpatched versions of the tool and could allow an unauthenticated threat actor to remotely access a machine’s file system and “execute arbitrary code with root privileges,” though Dell’s scoring indicates some user interaction is required. The company has not said the flaw is being exploited.

As Dell noted in an advisory published on Oct. 1, versions of the DSU tool prior to 2.3.0.0 contained an Improper Limitation of a Pathname to a Restricted Directory flaw, otherwise known as Path Traversal. If successfully exploited, this “may allow complete compromise of the vulnerable application and underlying operating system,” Dell warned.

The company has advised users to upgrade as soon as they can. The patched version of the DSU app can be downloaded from Dell’s website.

Four More DSU Flaws Fixed in the Same Update

This vulnerability is not the only one that Dell cautioned about in its advisory note. Alongside the 9.6-rated CVE-2026-86360 can be found CVE-2026-86361, which has a CVSS score of 8.2 and involves an Incorrect Permission Assignment for Critical Resource flaw that permits a low-privileged attacker to gain local access and potentially elevate their privileges.

Dell also outlined three other weaknesses in the DSU tool, ranging in severity from 7.3 to 8.2 on the CVSS scale. These flaws utilize privilege escalation and RCE that could be harnessed by threat actors with varying levels of system privilege and involve both local and remote access.

Dell advises all organizations running the DSU tool to upgrade to version 2.3.0.0 or as soon as possible.

This field is for validation purposes and should be left unchanged.

FREE NEWSLETTER

Cyber Weekly

Get curated cybersecurity news, threats and insights delivered free every Thursday.

Written By Written By
Alex Blake
Alex Blake Journalist

Alex Blake is a freelance journalist who has been covering the tech world for over a decade. In that time he's interviewed Apple VPs, reviewed countless products and taken deep dives into the pressing issues of the day. You'll find his work at TechRadar, Macworld, PC Gamer, T3 and more.