CVE-2026-35159
MEDIUM 5.3Dell Client Platform BIOS contains an Authentication Bypass by Primary Weakness vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information Disclosure.
No known exploitation, public exploit, or elevated probability at this time. Track for changes.
Exploitation likelihood
0.2%chance of exploitation in 30 days · 6th percentile
Impact if exploited
5.3CVSS 3.1 · MEDIUM
- ConfidentialityLow
- IntegrityHigh
- AvailabilityLow
What an attacker needs
- ⚠Access: Requires physical access to the device
- ✓Privileges: No account or privileges required
- ✓User interaction: No user interaction needed
- ⚠Complexity: Needs a race window or specific setup
✓ lowers the bar for an attacker · ⚠ raises it
Proof of concept & exploit code
- github-search Search GitHub for public PoC repos
Test against your own equipment
curl -s https://vulnpedia.com/cve/CVE-2026-35159/poc.jsonMachine-readable PoC index for this CVE (for automation).Listed for defensive triage, patch verification, and authorized testing on systems you own. Machine-readable: /cve/CVE-2026-35159/poc.json
Affected
Vendors Dell
Products Inspiron 15 3520 G15 5530 Alienware 16 Area 51 Aa16250 Alienware 16 Aurora Ac16250 Alienware 16x Aurora Ac16251 Alienware 18 Area 51 Aa18250 Alienware Area 51 Aat2250 Alienware Aurora Act1250 Alienware M15 R6 Alienware M15 R7 Alienware M16 R1 Alienware M16 R2
Weakness (CWE)
- CWE-305: : Authentication Bypass by Primary Weakness
CVSS vector
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L
All CVSS metrics
- MEDIUM 5.3 v3.1 · CNA Primary
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L - MEDIUM 5.3 v3.1 · NVD Secondary
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L