← Back to search

CVE-2026-49810

7.8 HIGH

Published 2026-09-21 · Updated 2026-09-21

AI risk analysis

Summary
The flaw allows a low-privileged attacker with local access to insert sensitive information into log files, potentially leading to information disclosure.
Exploitability
Exploitation is moderately difficult requiring local access but straightforward once obtained.
Blast radius
If exploited, the impact could be significant as it may lead to unauthorized exposure of sensitive data.
Prioritized remediation
Update Dell Command Powershell Provider to version 2.10.2 or later immediately.
info-disclocal-privlog-exploit

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Dell Command Powershell Provider (DCPP), versions prior to 2.10.2 contain an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-532

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.