Cyber Posture

CVE-2026-24510

MediumLPE

Published: 11 March 2026

Published
11 March 2026
Modified
16 March 2026
KEV Added
Patch
CVSS Score 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
EPSS Score 0.0001 2.7th percentile
Risk Priority 13 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2026-24510 is a medium-severity Improper Privilege Management (CWE-269) vulnerability in Dell Alienware Command Center. Its CVSS base score is 6.7 (Medium).

Operationally, exploitation aligns with the MITRE ATT&CK technique Exploitation for Privilege Escalation (T1068); ranked at the 2.7th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

Threat & Defense at a Glance

What attackers do: exploitation maps to Exploitation for Privilege Escalation (T1068).
Threat & Defense Details

Likely Mitigating ControlsAI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-269

Policy addresses roles, responsibilities, and privilege management to prevent improper privilege assignments.

addresses: CWE-269

Access supervision ensures privileges are assigned and managed without improper escalation or retention.

addresses: CWE-269

Assigning group/role memberships and access authorizations (privileges) while reviewing accounts addresses improper privilege management.

addresses: CWE-269

Enforces proper privilege management by requiring all decisions through the verified reference monitor.

addresses: CWE-269

By mandating division of duties across roles, the control enforces proper privilege management and prevents a single entity from controlling an entire sensitive process.

addresses: CWE-269

Implements core proper privilege management by restricting to only required rights.

addresses: CWE-269

Policy requires training on privilege management and least privilege, making it harder to exploit improper privilege management weaknesses.

addresses: CWE-269

Training covers proper privilege management practices, making incorrect privilege assignments less likely.

MITRE ATT&CK Enterprise TechniquesAI

T1068 Exploitation for Privilege Escalation Privilege Escalation
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.
Why these techniques?

Direct local privilege escalation via improper privilege management (CWE-269) in AWCC maps to exploitation for privilege escalation.

Confidence: HIGH · MITRE ATT&CK Enterprise v18.1

NVD Description

Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

Deeper analysisAI

Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, is affected by CVE-2026-24510, an Improper Privilege Management vulnerability classified under CWE-269. This flaw allows potential escalation of privileges and has a CVSS v3.1 base score of 6.7 (AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H), indicating medium severity with local attack vector, high attack complexity, low privileges required, and user interaction needed.

A low-privileged attacker with local access to the system can exploit this vulnerability to achieve elevation of privileges, potentially gaining higher-level access that enables full control over confidentiality, integrity, and availability of the affected system.

Dell has published security advisory DSA-2026-093, available at https://www.dell.com/support/kbdoc/en-us/000427573/dsa-2026-093, which provides details on mitigation and patching instructions for this issue.

Details

CWE(s)

Affected Products

dell
alienware command center
≤ 6.12.24.0

CVEs Like This One

CVE-2026-32655Same product: Dell Alienware Command Center
CVE-2026-25908Same product: Dell Alienware Command Center
CVE-2024-49561Same vendor: Dell
CVE-2026-22768Same vendor: Dell
CVE-2025-27688Same vendor: Dell
CVE-2026-27102Same vendor: Dell
CVE-2025-21105Same vendor: Dell
CVE-2024-48013Same vendor: Dell
CVE-2026-21418Same vendor: Dell
CVE-2025-46691Same vendor: Dell

References