DSA-2026-163: Security Update for Dell AppSync Vulnerabilities
Сводка: Dell AppSync remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
Данная статья применяется к
Данная статья не применяется к
Эта статья не привязана к какому-либо конкретному продукту.
В этой статье указаны не все версии продуктов.
Влияние
High
Подробные сведения
| Third-party Component | CVEs | More Information |
| KEYCLOAK | CVE-2022-4137 | https://nvd.nist.gov/vuln/search |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2026-22767 | Dell AppSync, version(s) 4.6.0, contain(s) an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H |
| CVE-2026-22768 | Dell AppSync, version(s) 4.6.0, contain(s) an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2026-22767 | Dell AppSync, version(s) 4.6.0, contain(s) an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H |
| CVE-2026-22768 | Dell AppSync, version(s) 4.6.0, contain(s) an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Затронутые продукты и исправление
| Product | Affected Versions | Remediated Versions | Link |
| Dell AppSync | Versions prior to 4.6.0.4 | Version 4.6.1.0 or later | https://www.dell.com/support/home/product-support/product/appsync/drivers |
| Product | Affected Versions | Remediated Versions | Link |
| Dell AppSync | Versions prior to 4.6.0.4 | Version 4.6.1.0 or later | https://www.dell.com/support/home/product-support/product/appsync/drivers |
История изменений
| Revision | Date | Description |
| 1.0 | 2026-04-01 | Initial Release |
Сведения об авторе и авторских правах
CVE-2026-22768: Dell would like to thank Marius Gabriel Mihai for reporting this issue.
CVE-2026-22767: Dell would like to thank falconCorrup for reporting this issue.
Связанная информация
Правовая оговорка
Затронутые продукты
AppSync, AppSyncСвойства статьи
Номер статьи: 000446965
Тип статьи: Dell Security Advisory
Последнее изменение: 01 Apr 2026
Получите ответы на свои вопросы от других пользователей Dell
Услуги технической поддержки
Проверьте, распространяются ли на ваше устройство услуги технической поддержки.