DSA-2026-163: Security Update for Dell AppSync Vulnerabilities
Sammanfattning: Dell AppSync remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
Den här artikeln gäller för
Den här artikeln gäller inte för
Den här artikeln är inte kopplad till någon specifik produkt.
Alla produktversioner identifieras inte i den här artikeln.
Påverkan
High
Information
| Third-party Component | CVEs | More Information |
| KEYCLOAK | CVE-2022-4137 | https://nvd.nist.gov/vuln/search |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2026-22767 | Dell AppSync, version(s) 4.6.0, contain(s) an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H |
| CVE-2026-22768 | Dell AppSync, version(s) 4.6.0, contain(s) an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2026-22767 | Dell AppSync, version(s) 4.6.0, contain(s) an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H |
| CVE-2026-22768 | Dell AppSync, version(s) 4.6.0, contain(s) an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Berörda produkter och åtgärder
| Product | Affected Versions | Remediated Versions | Link |
| Dell AppSync | Versions prior to 4.6.1.0 | Version 4.6.1.0 or later | https://www.dell.com/support/home/product-support/product/appsync/drivers |
| Product | Affected Versions | Remediated Versions | Link |
| Dell AppSync | Versions prior to 4.6.1.0 | Version 4.6.1.0 or later | https://www.dell.com/support/home/product-support/product/appsync/drivers |
Revideringshistorik
| Revision | Date | Description |
| 1.0 | 2026-04-01 | Initial Release |
| 2.0 | 2026-04-08 | Updated Affected versions |
Bekräftelser
CVE-2026-22768: Dell would like to thank Marius Gabriel Mihai for reporting this issue.
CVE-2026-22767: Dell would like to thank falconCorrup for reporting this issue.
Relaterad information
Juridisk friskrivning
Berörda produkter
AppSync, AppSyncArtikelegenskaper
Artikelnummer: 000446965
Artikeltyp: Dell Security Advisory
Senast ändrad: 07 apr. 2026
Få svar på dina frågor från andra Dell-användare
Supporttjänster
Kontrollera om din enhet omfattas av supporttjänster.