DSA-2026-163: Security Update for Dell AppSync Vulnerabilities
Podsumowanie: Dell AppSync remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
Ten artykuł dotyczy
Ten artykuł nie dotyczy
Ten artykuł nie jest powiązany z żadnym konkretnym produktem.
Nie wszystkie wersje produktu zostały zidentyfikowane w tym artykule.
Skutki
High
Szczegóły
| Third-party Component | CVEs | More Information |
| KEYCLOAK | CVE-2022-4137 | https://nvd.nist.gov/vuln/search |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2026-22767 | Dell AppSync, version(s) 4.6.0, contain(s) an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H |
| CVE-2026-22768 | Dell AppSync, version(s) 4.6.0, contain(s) an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2026-22767 | Dell AppSync, version(s) 4.6.0, contain(s) an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H |
| CVE-2026-22768 | Dell AppSync, version(s) 4.6.0, contain(s) an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Produkty, których dotyczy problem, i środki zaradcze
| Product | Affected Versions | Remediated Versions | Link |
| Dell AppSync | Versions prior to 4.6.0.4 | Version 4.6.1.0 or later | https://www.dell.com/support/home/product-support/product/appsync/drivers |
| Product | Affected Versions | Remediated Versions | Link |
| Dell AppSync | Versions prior to 4.6.0.4 | Version 4.6.1.0 or later | https://www.dell.com/support/home/product-support/product/appsync/drivers |
Historia zmian
| Revision | Date | Description |
| 1.0 | 2026-04-01 | Initial Release |
Podziękowania
CVE-2026-22768: Dell would like to thank Marius Gabriel Mihai for reporting this issue.
CVE-2026-22767: Dell would like to thank falconCorrup for reporting this issue.
Powiązane informacje
Zastrzeżenie prawne
Produkty, których dotyczy problem
AppSync, AppSyncWłaściwości artykułu
Numer artykułu: 000446965
Typ artykułu: Dell Security Advisory
Ostatnia modyfikacja: 01 kwi 2026
Znajdź odpowiedzi na swoje pytania u innych użytkowników produktów Dell
Usługi pomocy technicznej
Sprawdź, czy Twoje urządzenie jest objęte usługą pomocy technicznej.