CVE-2026-35159: Dell Client Platform BIOS Authentication Bypass – Physical Access Vulnerability
Dell Client Platform BIOS has a security flaw that bypasses authentication controls. An attacker with physical access to the computer could circumvent security checks, potentially exposing sensitive information stored in system memory or BIOS settings. This is not a remote vulnerability—the attacker must have hands-on access to the machine.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 5.3 MEDIUM · CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L
- Weaknesses (CWE)
- CWE-305
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-07-03 / 2026-07-07
NVD description (verbatim)
Dell Client Platform BIOS contains an Authentication Bypass by Primary Weakness vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information Disclosure.
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-35159 is an authentication bypass vulnerability in Dell Client Platform BIOS stemming from insufficient access controls (CWE-305). The flaw allows an unauthenticated adversary with physical access to skip or undermine BIOS-level authentication mechanisms. The CVSS 3.1 score of 5.3 (MEDIUM) reflects the attack vector requiring physical proximity (AV:P) and high complexity (AC:H), balanced against potential for information disclosure and integrity compromise. The vulnerability does not enable denial of service or remote exploitation.
Business impact
For organizations managing Dell client systems, this vulnerability affects data security posture in environments where physical device security cannot be guaranteed—such as open office layouts, shared lab spaces, or equipment in transit. A compromised BIOS can expose firmware-level secrets, allow configuration tampering, or facilitate persistence mechanisms. Risk is elevated in high-security sectors (finance, healthcare, government) where BIOS integrity is part of compliance controls. The medium CVSS score should not minimize concern; physical-access vulnerabilities are often high-impact in real-world breach scenarios.
Affected systems
The vulnerability exists in Dell Client Platform BIOS. Specific product models and affected versions were not disclosed in the source advisory; organization security teams must cross-reference their Dell client inventory against the vendor's official security bulletin to determine scope. Contact Dell support or check their security advisories for the complete list of impacted models and BIOS versions.
Exploitability
Exploitation requires physical access to the device and high technical complexity; this is not a trivial attack. An attacker cannot exploit this remotely. However, the barrier to exploitation is substantially lower than, for example, breaking hardware security modules. In environments with lax physical security or where devices are shared, unattended, or maintained by external vendors, exploitation risk materially increases. The vulnerability is not currently tracked in CISA's Known Exploited Vulnerabilities catalog.
Remediation
Dell will issue BIOS patches to restore proper authentication controls. Organizations should prioritize patching systems in physically vulnerable locations or handling sensitive data. Interim mitigations include enforcing strong physical access controls (device cages, locked cabinets), disabling BIOS settings that allow unauthenticated configuration changes, and requiring administrator password locks on BIOS entry. Verify patch availability through Dell's official security advisory before deployment.
Patch guidance
1. Consult Dell's security advisory for your specific Client Platform model to identify the patched BIOS version. 2. Plan patching during maintenance windows; BIOS updates typically require system reboot and brief downtime. 3. Test patches in a non-production environment first to confirm hardware compatibility and boot behavior. 4. After patching, verify BIOS settings remain intact and re-apply any custom configurations. 5. Document patch deployment and version levels for compliance reporting.
Detection guidance
Monitor BIOS access logs and audit trails for unauthorized authentication attempts or configuration changes. Tools such as hardware management consoles (iDRAC, ProSupport) may log BIOS access. Firmware integrity monitoring solutions can detect unauthorized modifications to BIOS code. Physical security monitoring (access logs, video surveillance) is equally important for detecting unauthorized device access. No specific exploit signatures are available yet, so detection relies on policy and physical controls.
Why prioritize this
This vulnerability merits prioritization in environments where physical device security is a known gap or where systems handle high-value data. The medium CVSS does not reflect real-world impact if an attacker gains hands-on access to unattended equipment in a sensitive facility. Organizations with strong physical security and robust BIOS password policies can defer patching slightly in favor of higher-severity remote vulnerabilities, but should not ignore it. Timeline for patching should balance workload, physical risk assessment, and compliance requirements.
Risk score, explained
The CVSS 3.1 score of 5.3 is driven by the physical-access requirement (AV:P), which significantly caps the attack vector score, and high complexity (AC:H). However, the vector also reflects integrity impact (I:H) alongside confidentiality and availability impact, raising the overall score above CVSS Low. The medium rating appropriately captures that exploitation is feasible in real-world scenarios where attackers have physical presence but not trivial. Organizations must contextualize this score against their own physical security posture and data sensitivity.
Frequently asked questions
Can this vulnerability be exploited remotely or over a network?
No. CVE-2026-35159 requires physical access to the device. There is no remote exploitation path. Threat actors must be present at the machine to attempt an attack.
What is 'authentication bypass by primary weakness' and why does it matter?
This means the BIOS authentication mechanism has a fundamental design flaw (not just a missing password), allowing attackers to skip or undermine access controls entirely. Unlike a weak password, a primary weakness affects all instances of the vulnerable BIOS version. Once patched, the underlying flaw is closed for all users.
If my organization has strict physical access controls, can we delay patching?
Physical access controls significantly reduce risk, but breaches do occur—insider threats, vendor maintenance, theft, or social engineering can grant physical access. Delayed patching is a business decision that should align with your risk tolerance and compliance requirements. We recommend prioritizing systems in lower-security areas or those handling sensitive data, then patch the rest within a standard maintenance cycle.
How do I know which Dell systems I own are affected?
Consult Dell's official security advisory, which lists affected Client Platform models and BIOS versions. Cross-reference your inventory against that list. Dell's website or your account team can provide the advisory if you don't have it. Do not rely on CVE descriptions alone for product scope.
This analysis is for informational purposes and does not constitute legal, compliance, or professional security advice. Risk scores and severity ratings are based on published CVSS metrics and may not reflect your organization's specific environment, data classification, or threat model. Verification of patch availability, affected product models, and remediation steps must be confirmed against Dell's official security advisory. SEC.co does not guarantee the accuracy, completeness, or timeliness of vulnerability intelligence and recommends independent verification before operational decisions. Source: NVD (public-domain), retrieved 2026-08-11. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2025-7064MEDIUMABB Freelance Authentication Bypass (CVSS 6.6)
- CVE-2026-9798MEDIUMKeycloak Account Lockout Bypass via CIBA Flow
- CVE-2026-41052HIGHSUSE Rancher Privilege Escalation (8.8 HIGH)
- CVE-2016-20064MEDIUMWP Vault 0.8.6.6 Arbitrary File Read via Directory Traversal
- CVE-2016-20067MEDIUMWordPress CP Polls CSRF Vulnerability
- CVE-2016-20070MEDIUMPrivilege Escalation & Stored XSS in WordPress Booking Calendar Contact Form 1.0.23
- CVE-2016-20074MEDIUMWordPress Lazy Content Slider CSRF Vulnerability – Patch & Detection Guide
- CVE-2016-20077MEDIUMWordPress Photocart Link Plugin Local File Inclusion Vulnerability