Steal or buy a used Dell, and on a whole range of them you can read the admin password back off a chip inside. Two researchers found that Dell stored that password with a weak, reversible scramble, then left the key to unscramble it sitting right beside it.
This is not a remote break-in. Someone needs the machine in their hands, plus a clip and a cheap programmer to read the chip, or their own operating system booted on it. Once they have a copy of what is on the chip, a password up to 12 characters usually falls straight out.
How the password leaks
A password is normally kept as a one-way scramble, so the machine can check it without ever storing the real word. Dell instead kept the real password under a scramble you can run backwards, and did not even scramble the first letter.
It gets worse. For any password up to 12 characters, the blank space in the storage slot spells out the key that reverses the scramble. An attacker reads the chip, grabs the key sitting next to the password, and the real one appears. Longer passwords stay partly hidden, though an older short password can reveal the rest if both passwords start with the same character.
When it actually bites
If you own an affected Dell that could end up in the wrong hands, lost, stolen, or resold, this is your problem. Wiping the drive does nothing, because the BIOS password does not live on the drive. It lives in the flash chip.
Getting the real password back is worse than just clearing it, because people reuse passwords. If your BIOS password matches your login, whoever pulls it off the chip now has that too. The researchers confirmed several older Dells were affected, plus a Wyse 5070 thin client still unpatched on July 10, and the full range is still being confirmed.
What Dell fixed
The two researchers, from the security firms MDSec and AmberWolf, reported the flaw in March 2026 and published the details on July 10. Dell tracks it as CVE-2026-40639 and patched an initial set of products in June, with more to follow. Some newer models that the researchers tested used a stronger method.
Where Dell has no update yet, the researchers suggest a separate BIOS password on each machine and disk encryption tied to the machine's own security chip, though even that is no guarantee once someone has BIOS access. But storing a password you can reverse, with the key parked right next to it, was never going to hold. Now the method is public.



