Junglewise Threat Intelligence

CVE-2026-40713: Dell ThinOS improper access control leading to information exposure

CVE-2026-40713 · Severity: medium · CVSS 6.1 · Published 2026-06-02

Technologies: Dell ThinOS, Dell ThinOS 10. Vendors: Dell.

Executive brief

Dell ThinOS is an operating system used in thin client devices, which are compact computers typically used to connect to remote virtual desktops. A security flaw in certain versions could allow an individual with physical access to the device to bypass security controls and view sensitive information. This could lead to the exposure of user data or system configuration details if an unauthorized person gains hands-on access to the hardware.

Technical details

Dell ThinOS 10 contains an improper access control vulnerability (CWE-284) in versions prior to 2602_10.0765. The vulnerability is exploitable by an unauthenticated attacker who has physical access to the affected thin client device. Successful exploitation could lead to unauthorized information exposure and potentially impact system integrity. Dell has released firmware version 2602_10.0765_T10 or later to remediate this issue across various Latitude, OptiPlex, and Wyse hardware platforms.

Affected products

  • Dell ThinOS 10 prior to 2602_10.0765_T10

Timeline

  • 2026-05-15: patched: Remediated firmware version released
  • 2026-06-02: disclosed: Initial public advisory published

References

Related threats