Dell Alienware Purchased Apps <1.1.31 Improper Link Follow
CVE-2026-27105 Published on April 29, 2026
Dell/Alienware Purchased Apps, versions prior to 1.1.31.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary File Write
Vulnerability Analysis
CVE-2026-27105 can be exploited with local system access, and requires small amount of user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, a high impact on integrity and availability.
Weakness Type
What is an insecure temporary file Vulnerability?
The software attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
CVE-2026-27105 has been classified to as an insecure temporary file vulnerability or weakness.
Affected Versions
Dell/Alienware Purchased Apps:- Before 1.1.31.0 is affected.