CVE-2026-41116
No sign of exploitation. No public exploitation artifact known so far.
Dell Inventory Collector Client versions before 13.8.0 have a flaw where it follows symbolic links without proper checks, allowing an attacker with local access to write files anywhere on the system. This could be used to compromise system integrity or execute malicious code.
The vulnerability is a classic link-following issue (CWE-1386) in Dell Inventory Collector Client <13.8.0. A low-privileged local attacker can exploit a race condition or predictable path to create a symbolic link that the application follows, resulting in arbitrary file write with the application's privileges. This requires local filesystem access and could lead to privilege escalation or system compromise.