CVE-2026-35159

MEDIUMCVSS 5.3/10EPSS 0.16%

Last modified

CVE-2026-35159 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Dell Client Platform BIOS contains an Authentication Bypass by Primary Weakness vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information Disclosure.. EPSS estimates a 0.16% chance of exploitation in the next 30 days.

Description

Dell Client Platform BIOS contains an Authentication Bypass by Primary Weakness vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information Disclosure.

Metrics

CVSS 3.1
5.3/10

CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L

EPSS Probability
0.16%

5.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
DellInspiron 15 3520< 1.41.0 or later
DellG15 5530< 1.33.0 or later
DellAlienware 16 Area-51 AA16250< 2.4.1 or later
DellAlienware 16 Aurora AC16250< 1.13.0 or later
DellAlienware 16X Aurora AC16251< 2.4.0 or later
DellAlienware 18 Area-51 AA18250< 2.4.1 or later
DellAlienware Area-51 AAT2250< 1.17.2 or later
DellAlienware Aurora ACT1250< 1.16.2 or later
DellAlienware m15 R6< 1.44.0 or later
DellAlienware m15 R7< 1.40.0 or later
DellAlienware m16 R1< 1.34.0 or later
DellAlienware m16 R2< 1.21.0 or later
DellAlienware m18 R1< 1.34.0 or later
DellAlienware M18 R2< 1.22.0 or later
DellAlienware x14 R2< 1.32.0 or later
DellAlienware x16 R1< 1.32.0 or later
DellAlienware X16 R2< 1.22.0 or later
DellChengMing 3900< 1.40.0 or later
DellChengMing 3910/3911< 1.36.0 or later
DellDell 14 DC14250< 1.7.0 or later
Dell14 Plus 2-in-1 DB04250< 1.13.0 or later
Dell14 Plus DB14250< 1.13.0 or later
Dell15 DC15250< 1.10.0 or later
Dell16 Plus 2-in-1 DB06250< 1.13.0 or later
Dell16 Plus DB16250< 1.13.0 or later
Dell24 All-in-One EC24250< 1.15.0 or later
Dell27 All-in-One EC27250< 1.15.0 or later
DellG15 5510< 1.40.0 or later
DellG15 5511< 1.43.0 or later
DellG15 5520< 1.41.0 or later
DellG16 7620< 1.41.0 or later
DellG16 7630< 1.33.0 or later
DellPro 13 Plus PB13250< 2.13.4 or later
DellPro 13 Plus PB13255< 1.15.0 or later
DellPro 13 Premium PA13250< 2.13.4 or later
DellPro 14 Essential PV14250< 1.6.0 or later
DellPro 14 PC14250< 1.15.2 or later
DellPro 14 Plus PB14250< 2.13.4 or later
DellPro 14 Plus PB14255< 1.15.0 or later
DellPro 14 Premium PA14250< 2.13.4 or later
DellPro 16 PC16250< 1.15.2 or later
DellPro 16 Plus PB16250< 2.13.4 or later
DellPro 16 Plus PB16255< 1.15.0 or later
DellPro 24 All-In-One Plus QB24250 / Pro 24 All-In-One QC24250 / Pro 24 All-In-One QC24251< 1.15.1 or later
DellPro Laptop PC14250< 1.15.2 or later
DellPro Laptop PC16250< 1.15.2 or later
DellPro Max 14 MC14250< 1.14.1 or later
DellPro Max 14 MC14255< 2.4.0 or later
DellPro Max 16 MC16250< 1.14.1 or later
DellPro Max 16 MC16255< 2.4.0 or later

Showing 50 of 230 affected configurations. See the CNA advisory for the full list.

References

Timeline

Published
Last Modified
Status
Awaiting Analysis

Frequently Asked Questions

What is CVE-2026-35159?
Dell Client Platform BIOS contains an Authentication Bypass by Primary Weakness vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information Disclosure.
How severe is CVE-2026-35159?
CVE-2026-35159 has a CVSS score of 5.3/10 (MEDIUM severity). The EPSS model estimates a 0.16% probability of exploitation in the next 30 days.
How do I fix CVE-2026-35159?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-35159?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST