← All CVEs

CVE-2026-35159

MEDIUM 5.3

Published 2026-07-03 · Last modified 2026-07-07

Dell Client Platform BIOS contains an Authentication Bypass by Primary Weakness vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information Disclosure.

NO EXPLOITATION SIGNALS

No known exploitation, public exploit, or elevated probability at this time. Track for changes.

Exploitation likelihood

0.2%chance of exploitation in 30 days · 6th percentile

○ In CISA KEV ○ Public exploit / PoC

Impact if exploited

5.3CVSS 3.1 · MEDIUM

  • ConfidentialityLow
  • IntegrityHigh
  • AvailabilityLow

What an attacker needs

  • Access: Requires physical access to the device
  • Privileges: No account or privileges required
  • User interaction: No user interaction needed
  • Complexity: Needs a race window or specific setup

✓ lowers the bar for an attacker · ⚠ raises it

Proof of concept & exploit code

Test against your own equipment

curl -s https://vulnpedia.com/cve/CVE-2026-35159/poc.jsonMachine-readable PoC index for this CVE (for automation).

Listed for defensive triage, patch verification, and authorized testing on systems you own. Machine-readable: /cve/CVE-2026-35159/poc.json

Affected

Vendors Dell

Products Inspiron 15 3520 G15 5530 Alienware 16 Area 51 Aa16250 Alienware 16 Aurora Ac16250 Alienware 16x Aurora Ac16251 Alienware 18 Area 51 Aa18250 Alienware Area 51 Aat2250 Alienware Aurora Act1250 Alienware M15 R6 Alienware M15 R7 Alienware M16 R1 Alienware M16 R2

Weakness (CWE)

  • CWE-305: : Authentication Bypass by Primary Weakness

CVSS vector

CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L

All CVSS metrics

  • MEDIUM 5.3 v3.1 · CNA Primary
    CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L
  • MEDIUM 5.3 v3.1 · NVD Secondary
    CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L

Sources: NVD · CVE.org · EPSS