Junglewise Threat Intelligence

CVE-2026-41120: Dell Wyse Management Suite remote code execution

CVE-2026-41120 · Severity: critical · CVSS 9.8 · Published 2026-06-25

Technologies: Dell Wyse Management Suite. Vendors: Dell.

Executive brief

Dell Wyse Management Suite is a centralized solution for managing and configuring Dell thin clients and other endpoints. A critical vulnerability allows an attacker to remotely execute malicious code on the management server. This could lead to a total compromise of the management platform, allowing unauthorized access to sensitive configuration data and control over managed devices.

Technical details

Dell Wyse Management Suite (WMS) versions prior to 5.5 HF1 are vulnerable to an 'Acceptance of Extraneous Untrusted Data With Trusted Data' flaw (CWE-349). The vulnerability exists because the application fails to properly distinguish between trusted internal data and untrusted external input, allowing an attacker to inject malicious data that is subsequently processed as trusted. This can be exploited by a remote attacker with low privileges (or no privileges, as indicated by the CVSS vector PR:N) to achieve Remote Code Execution (RCE). The attack vector is network-based and requires no user interaction. Dell has released WMS version 5.5 HF1 to address this issue.

Affected products

  • Dell Wyse Management Suite Versions prior to 5.5 HF1

Timeline

  • 2026-05-08: patched: Release date of remediated version 5.5 HF1
  • 2026-06-16: disclosed: Initial release of Dell Security Advisory DSA-2026-225
  • 2026-06-25: advisory: NVD publication date

References

Related threats