PT-2026-5387 · Dell · Dell Unityvsa

J. Liu

·

Published

2026-01-30

·

Updated

2026-01-30

·

CVE-2026-22277

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell UnityVSA versions prior to 5.4
Description Dell UnityVSA versions 5.4 and earlier are susceptible to an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') issue. A local attacker with low privileges could potentially exploit this, resulting in arbitrary command execution with root privileges.
Recommendations Update Dell UnityVSA to a version later than 5.4.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-22277

Affected Products

Dell Unityvsa