Executive brief
Dell ThinOS is an operating system used in thin client devices, which are compact computers typically used to connect to remote virtual desktops. A security flaw in certain versions could allow an individual with physical access to the device to bypass security controls and view sensitive information. This could lead to the exposure of user data or system configuration details if an unauthorized person gains hands-on access to the hardware.
Technical details
Dell ThinOS 10 contains an improper access control vulnerability (CWE-284) in versions prior to 2602_10.0765. The vulnerability is exploitable by an unauthenticated attacker who has physical access to the affected thin client device. Successful exploitation could lead to unauthorized information exposure and potentially impact system integrity. Dell has released firmware version 2602_10.0765_T10 or later to remediate this issue across various Latitude, OptiPlex, and Wyse hardware platforms.
Affected products
- Dell ThinOS 10 prior to 2602_10.0765_T10
Timeline
- 2026-05-15: patched: Remediated firmware version released
- 2026-06-02: disclosed: Initial public advisory published