CVE-2026-32655
Published: 27 April 2026
Summary
CVE-2026-32655 is a medium-severity Least Privilege Violation (CWE-272) vulnerability in Dell Alienware Command Center. Its CVSS base score is 5.3 (Medium).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploitation for Privilege Escalation (T1068); ranked at the 0.3th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified are NIST 800-53 AC-6 (Least Privilege) and SI-2 (Flaw Remediation).
Threat & Defense at a Glance
Threat & Defense Details
Mitigating Controls (NIST 800-53 r5)AI
Directly enforces the principle of least privilege, preventing low-privileged local attackers from escalating privileges via this violation in AWCC.
Requires identification, reporting, and correction of flaws like this least privilege violation by applying the vendor security update to AWCC 6.13.8.0 or later.
Mandates enforcement of approved access authorizations, mitigating privilege escalations from improper access controls in vulnerable AWCC versions.
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
Local least-privilege violation enabling direct privilege escalation from low-privileged context matches T1068 Exploitation for Privilege Escalation.
NVD Description
Dell Alienware Command Center (AWCC), versions prior to 6.13.8.0, contain a Least Privilege Violation vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Deeper analysisAI
CVE-2026-32655 is a Least Privilege Violation vulnerability (CWE-272) in Dell Alienware Command Center (AWCC), affecting versions prior to 6.13.8.0. Published on 2026-04-27, the issue has a CVSS v3.1 base score of 5.3 (AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L), rated as medium severity.
A low-privileged attacker with local access could potentially exploit this vulnerability to achieve elevation of privileges. The attack requires local access and high complexity, with no user interaction needed, resulting in high impact to integrity and low impact to availability, but no confidentiality impact and unchanged scope.
Dell's security advisory DSA-2026-192 details a security update for AWCC 6.x addressing multiple vulnerabilities, including CVE-2026-32655. Mitigation requires updating to version 6.13.8.0 or later.
Details
- CWE(s)