Executive brief
Dell Wyse Management Suite is a centralized solution for managing and configuring Dell thin clients. A security vulnerability in versions prior to 2605 could allow a user with low-level access to the local system to gain unauthorized access to sensitive files or data. This could lead to a compromise of the management console's integrity and the confidentiality of the managed environment.
Technical details
Dell Wyse Management Suite (WMS) and WMS Repository versions prior to 2605 are vulnerable to an Improper Link Resolution Before File Access (CWE-59) flaw. The vulnerability occurs when the application fails to properly validate file links (such as symbolic links) before performing file operations. A low-privileged attacker with local access to the host operating system can exploit this by creating malicious links that point to sensitive files, potentially leading to unauthorized read, write, or delete operations with the privileges of the WMS service. This can result in a full compromise of confidentiality, integrity, and availability (CVSS 7.8). The issue is resolved in version 2605.
Affected products
- Dell Wyse Management Suite (WMS) prior to 2605
- Dell Wyse Management Suite Repository prior to 2605
Timeline
- 2026-06-01: patched: Remediated versions released
- 2026-06-16: advisory: Initial release of DSA-2026-247
- 2026-06-22: disclosed: NVD publication date