CVE-2026-27105
Analyzed
Analyzed - Analysis Complete
Improper Link Resolution Leading to Arbitrary File Write in Dell Alienware Purchased Apps
Publication date: 2026-04-29
Last updated on: 2026-05-05
Assigner: Dell
Description
Description
Dell/Alienware Purchased Apps, versions prior to 1.1.31.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary File Write
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| dell | dell/alienware_purchased_apps | to 1.1.31.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-59 | The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource. |