Junglewise Threat Intelligence

CVE-2026-44273: Dell Wyse Management Suite use of default credentials

CVE-2026-44273 · Severity: medium · CVSS 6 · Published 2026-06-22

Technologies: Dell Wyse Management Suite. Vendors: Dell.

Executive brief

Dell Wyse Management Suite, a centralized solution for managing Dell thin clients, contains a vulnerability where default credentials are used for a component of the system. A high-privileged attacker with local access to the management server could use these known credentials to access sensitive information or modify system settings. This could lead to the exposure of management data or unauthorized changes to the thin client environment.

Technical details

Dell Wyse Management Suite (WMS) versions prior to 2605 are vulnerable to the use of default credentials (CWE-1392). The vulnerability allows an attacker who already possesses high-privileged local access to the system to leverage these hardcoded or default credentials to gain further unauthorized access. Successful exploitation can lead to information disclosure and unauthorized modification of data (Integrity impact). The attack vector is local, requiring the attacker to have an existing foothold on the management server. Dell has addressed this issue in WMS version 2605.

Affected products

  • Dell Wyse Management Suite (WMS) prior to 2605

Timeline

  • 2026-06-16: advisory: Initial release of Dell Security Advisory DSA-2026-247
  • 2026-06-22: disclosed: NVD publication date

References

Related threats