Executive brief
Dell ThinOS is an operating system used in thin client devices for accessing virtual desktops and cloud applications. A security flaw allows a user with low-level access to the device to execute unauthorized commands with higher privileges. This could allow an attacker to take full control of the device, potentially compromising user data or the corporate network connection.
Technical details
A command injection vulnerability (CWE-77) exists in Dell ThinOS 10 due to improper neutralization of special elements used in a command. An attacker with local access and low-level privileges can exploit this flaw to execute arbitrary commands with elevated permissions. The vulnerability is triggered without requiring user interaction. Dell has released remediated firmware versions (2602_10.0573_T10 or later) for affected Latitude, OptiPlex, and Wyse hardware platforms.
Affected products
- Dell ThinOS 10 Versions prior to 2602_10.0573_T10
Timeline
- 2026-03-09: patched: Remediated versions released by Dell.
- 2026-03-16: disclosed: Initial NVD publication.