# Dell System Update (DSU) path traversal CVE-2026-86360 (CVSS 9.6) allows unauthenticated root code execution, plus four high-severity flaws fixed in DSU 2.3.0.0

> Dell fixed five vulnerabilities in Dell System Update (DSU), the CLI firmware/driver update tool for PowerEdge servers, in advisory DSA-2026-324. The critical CVE-2026-86360 is a path traversal (CVSS 9.6) that lets an unauthenticated remote attacker run code as root; four high-severity flaws (certificate validation, path traversal, permission/access-control bugs) enable RCE and local privilege escalation. No exploitation or public PoC has been reported.

- **Published:** 2026-10-05T00:00:00Z
- **Last reviewed:** 2026-10-05T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2935
- **ID:** TL-2026-2935
- **Severity:** CRITICAL (CVSS 9.6)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 14 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-86360, CVE-2026-63697, CVE-2026-71168, CVE-2026-86361, CVE-2026-86362

## Description

On 2026-10-01 Dell published DSA-2026-324 (KB 000515843) covering Dell System Update (DSU), the command-line tool used to deploy Dell Update Packages (firmware, BIOS and driver updates) to Dell PowerEdge servers. All DSU versions prior to 2.3.0.0 are affected by all five CVEs; DSU 2.3.0.0 or later fixes them (download driverid J9TK1). Dell recommends customers upgrade at the earliest opportunity. BleepingComputer covered the advisory on 2026-10-05.

CVE-2026-86360 (CVSS 9.6, CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H) is a path traversal weakness. Dell states that an unauthenticated attacker with remote access could potentially exploit it, leading to filesystem access; the flaw can be leveraged for arbitrary code execution with root privileges and may allow complete compromise of the vulnerable application and underlying operating system. The CVSS vector indicates user interaction is required and scope is changed; the specific trigger is not detailed in the advisory.

Four further high-severity flaws were fixed: CVE-2026-86361 (CVSS 8.2, AV:L/AC:L/PR:L/UI:R/S:C, incorrect permission assignment for a critical resource) and CVE-2026-86362 (CVSS 8.2, same vector, improper access control), both enabling local privilege escalation by a low-privileged user; CVE-2026-63697 (CVSS 7.6, AV:N/AC:H/PR:H/UI:R/S:C, improper certificate validation; a high-privileged remote attacker could achieve remote code execution); and CVE-2026-71168 (CVSS 7.3, AV:L/AC:L/PR:L/UI:R/S:U, path traversal; a low-privileged local attacker could achieve code execution). Reporters credited by Dell: Ori Gabriel (CVE-2026-63697, CVE-2026-86360), saltedfish (CVE-2026-86361, CVE-2026-86362) and Nir Yehoshua of Cipher Security Labs (CVE-2026-71168).

No active exploitation has been reported, none of the five CVEs appears in the CISA KEV catalog (catalog version 2026.10.04 checked), the NVD API returned no record for CVE-2026-86360 at research time, and no public proof-of-concept had surfaced. Dell's advisory lists no workarounds. BleepingComputer notes that state-sponsored actors have previously exploited other Dell flaws (Lazarus via CVE-2021-21551 in the dbutil driver; UNC6201 via CVE-2026-22769 in Dell RecoverPoint since mid-2024, linked to Silk Typhoon); these are historical context, not attributed to the DSU flaws. DSU runs with elevated privileges on server infrastructure, so successful exploitation would give control of firmware/driver update paths on PowerEdge hosts. No network IOCs are published; detection should focus on DSU process/file behavior and version inventory.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1203 Exploitation for Client Execution
- T1548 Abuse Elevation Control Mechanism
- T1557 Adversary-in-the-Middle
- T1005 Data from Local System

## Sources

- [New Dell System Update flaw lets hackers gain root privileges](https://www.bleepingcomputer.com/news/security/new-dell-system-update-flaw-lets-hackers-gain-root-privileges/)
- [DSA-2026-324: Dell System Update security advisory](https://www.dell.com/support/kbdoc/en-us/000515843)
- [Dell System Update 2.3.0.0 download](https://www.dell.com/support/home/en-us/drivers/DriversDetails?driverid=J9TK1)
- [Dell System Update Flaw CVE-2026-86360 Could Allow Root Code Execution](https://securityonline.info/dell-system-update-cve-2026-86360/)
- [CVE-2026-86362 - vulnerability database](https://vulners.com/cve/CVE-2026-86362)
- [CVE-2026-86361 - vulnerability database](https://vulners.com/cve/CVE-2026-86361)
- [Dell System Update (DSU) product documentation](https://www.dell.com/support/kbdoc/it-it/000130590/dell-system-update-dsu)
- [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json)
- [NVD CVE API record query for CVE-2026-86360](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-86360)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2935
