
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24502 is an Uncontrolled Search Path Element vulnerability (CWE-427) in Dell Command | Intel vPro Out of Band, affecting all versions prior to 4.7.0. A low-privileged local attacker can exploit this flaw to achieve elevation of privileges on the affected system. The vulnerability was published on March 3, 2026, with a patch available via Dell Security Advisory DSA-2026-106. It carries a CVSS v3.1 base score of 7.8 (High) per NVD, and 8.8 (High) per ENISA's EUVD scoring (Dell Advisory, ENISA EUVD).
The vulnerability is classified as CWE-427 (Uncontrolled Search Path Element), meaning the application uses a search path that can be influenced by an attacker to load malicious resources such as DLLs or executables. An attacker with low-privileged local access can place a malicious file in a directory that the application searches before the legitimate path, causing the application to load and execute attacker-controlled code. This technique aligns with MITRE ATT&CK techniques T1574.001 (DLL Search Order Hijacking) and T1574.007 (Path Interception by PATH Environment Variable), and CAPEC-471 (Search Order Hijacking). No user interaction is required for exploitation (Dell Advisory, The Hacker Wire).
Successful exploitation allows a low-privileged local attacker to escalate privileges on the affected system, resulting in high impact to confidentiality, integrity, and availability. An attacker could gain elevated access to sensitive system resources, modify critical configurations, or disrupt system operations. The scope of impact is limited to the affected host, but elevated privileges could facilitate further lateral movement within a network environment (Dell Advisory, ENISA EUVD).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (The Hacker Wire). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.006%, indicating a very low probability of exploitation in the near term. Exploitation requires local access with low privileges and no user interaction, limiting the attack surface to authenticated local users or those who have already achieved initial access.
Dell has released version 4.7.0 of Dell Command | Intel vPro Out of Band to address this vulnerability, as documented in security advisory DSA-2026-106. Organizations should upgrade to version 4.7.0 or later as the primary remediation. As interim mitigations, restrict local system access to trusted users only, audit and restrict write permissions on directories included in the application's search path, and monitor systems for suspicious privilege escalation activity (Dell Advisory).
Coverage of CVE-2026-24502 has been limited to automated vulnerability tracking platforms and security news aggregators. The Hacker Wire published a brief report on the elevation of privilege issue, and the vulnerability was noted on social media platforms including Bluesky and Mastodon by security-focused accounts (The Hacker Wire). No significant researcher commentary or broader media coverage has been identified, consistent with the low EPSS score and absence of active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."