DSA-2026-267: Security Updates for Dell Display and Peripheral Manager (DDPM Mac) for Multiple Vulnerabilities
Summary: Dell Display and Peripheral Manager (DDPM Mac) remediation is available for multiple vulnerabilities that could be exploited by malicious users to compromise the affected system.
Impact
High
Details
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2026-46735 |
Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution.
|
7.8 |
|
|
CVE-2026-46734 |
Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Certificate Validation vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass.
|
7.3 |
|
|
CVE-2026-46732 |
Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain a Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
|
6.7 |
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2026-46735 |
Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution.
|
7.8 |
|
|
CVE-2026-46734 |
Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Certificate Validation vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass.
|
7.3 |
|
|
CVE-2026-46732 |
Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain a Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
|
6.7 |
Affected Products & Remediation
|
Product |
Affected Versions |
Remediated Versions |
Release Date (MM/DD/YYYY) |
Link |
|
Dell Display and Peripheral Manager (DDPM Mac) |
Versions prior to 2.3 |
Version 2.3 and later |
06/11/2026 |
Support for Dell Display and Peripheral Manager | Drivers & Downloads | Dell US |
|
Product |
Affected Versions |
Remediated Versions |
Release Date (MM/DD/YYYY) |
Link |
|
Dell Display and Peripheral Manager (DDPM Mac) |
Versions prior to 2.3 |
Version 2.3 and later |
06/11/2026 |
Support for Dell Display and Peripheral Manager | Drivers & Downloads | Dell US |
Revision History
"
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2026-06-16 | Initial Release |
Acknowledgements
CVE-2026-46732: Dell Technologies would like to thank maikroservice for reporting this issue.
CVE-2026-46734, CVE-2026-46734: Dell Technologies would like to thank Ori Gabriel for reporting this issue.