DSA-2026-215: Security Update for Dell SupportAssist for PCs (Home and Business), Dell Optimizer, Dell Trusted Device, Dell/Alienware Update, Alienware Command Center, Dell Command | Update for an Improper Link Resolution Before File Access Vulnerability
Summary: Dell released remediation for an Improper Link Resolution Before File Access ('Link Following') Vulnerability in Dell Inventory Collector invoked within Dell SupportAssist for PCs (Home and Business), Dell Optimizer, Dell Trusted Device, Dell Update, Alienware Update, Alienware Command Center, Dell Command | Update that may be exploited by malicious users to compromise the affected system. ...
Impact
Medium
Details
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2026-41116 | Dell Inventory Collector Client, versions prior to 13.8.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary File Write. | 6.3 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2026-41116 | Dell Inventory Collector Client, versions prior to 13.8.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary File Write. | 6.3 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H |
Affected Products & Remediation
|
Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Release Date (MM/DD/YYYY) |
Link |
|
Dell Inventory Collector |
Software |
Versions prior to 13.8.0 |
Version 13.8.0 or later |
04/30/2026 |
https://www.dell.com/support/kbdoc/en-us/000123347/drivers-and-downloads-faqs |
|
Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Release Date (MM/DD/YYYY) |
Link |
|
Dell Inventory Collector |
Software |
Versions prior to 13.8.0 |
Version 13.8.0 or later |
04/30/2026 |
https://www.dell.com/support/kbdoc/en-us/000123347/drivers-and-downloads-faqs |
Dell Command | Update, Dell Update, Alienware Update, Dell Optimizer, Dell Trusted Device and Dell SupportAssist for PCs (Home and Business) automatically updates Inventory Collector without any user interaction.
To verify you are running the remediated version of Inventory Collector within these products, follow below steps:
- Go to C:\Program Files (x86)\Dell\UpdateService\Service\InvColPC\
- Right Click on the invcol.exe file, click on Properties, then go to Details tab.
- Verify Product Version is 13.8.0 or later.
- If yes, no further action is required.
- If version is not 13.8.0 or later, perform the steps to auto-update Inventory Collector below for the relevant product:
SupportAssist for PCs (Home and Business)
- Windows Search and select SupportAssist
- Open the SupportAssist application
- Navigate to “Get Drivers and Downloads” and click on “Run Now”.
Dell Command| Update/ Dell Update/ Alienware Update/ Dell Optimizer/ Dell Trusted Device
- Windows Search and select Dell Command| Update/ Dell Update/ Alienware Update/ Dell Optimizer/ Dell Trusted Device
- Open Dell Command| Update/ Dell Update/ Alienware Update/ Dell Optimizer/ Dell Trusted Device
- Click on “Check”.
Revision History
"
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2026-06-08 | Initial Release |
Acknowledgements
CVE-2026-41116: Dell Technologies would like to thank falconCorrup for reporting this issue.