Junglewise Threat Intelligence

CVE-2026-40715: Dell ThinOS 10 privilege escalation via improper access control

CVE-2026-40715 · Severity: high · CVSS 7.8 · Published 2026-06-02

Technologies: Dell ThinOS 10, Dell ThinOS. Vendors: Dell.

Executive brief

Dell ThinOS is an operating system used in thin-client devices for accessing virtual desktops and cloud applications. A security flaw in this system allows a user with low-level access to gain higher administrative privileges. This could allow an unauthorized person to take full control of the device, potentially compromising sensitive data or disrupting business operations.

Technical details

Dell ThinOS 10 versions prior to 2602_10.0765 contain an improper access control vulnerability (CWE-284). The flaw exists within the proprietary code of the operating system. A local attacker with low-level privileges can exploit this weakness to escalate their permissions to a higher level, potentially gaining full administrative control. The attack requires local access but no user interaction. Dell has released remediated firmware versions (2602_10.0765_T10 or later) for affected Latitude, OptiPlex, and Wyse hardware platforms.

Affected products

  • Dell ThinOS 10 Versions prior to 2602_10.0765_T10

Timeline

  • 2026-05-15: patched: Remediated firmware versions released.
  • 2026-06-02: disclosed: Initial advisory publication.

References

Related threats