AUGUST 23, 2026
Live Feed
Back to database
Case File

CVE-2026-67268

MEDIUM · CVSS 6.5 EPSS 0.10% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

Dell Command Update versions prior to 5.7.1 are vulnerable to an improper restriction of XML External Entity (XXE) reference, which could allow a low-privileged attacker with local access to exploit the system. This could result in privilege escalation and server-side request forgery, potentially compromising sensitive data or system integrity. Organizations using affected versions should prioritize patching to mitigate these risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-67268
Severity
MEDIUM
CVSS
6.5
EPSS
0.10%

Original NVD Description

Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges and Server-side request forgery.

Related CVEs

Other vulnerabilities affecting the same vendor(s)