Executive brief
Dell ThinOS 10, an operating system used in thin client devices for secure cloud and VDI access, contains a vulnerability where an obsolete user interface feature remains accessible. A user with low-level access to the device could exploit this legacy feature to gain unauthorized access to the system. This could potentially allow an attacker to bypass security restrictions or access sensitive information on the local terminal.
Technical details
Dell ThinOS 10 is affected by an 'Obsolete Feature in UI' vulnerability (CWE-448). The flaw exists because a legacy or deprecated feature remains present in the user interface, providing a path for unauthorized actions. A local attacker with low privileges can interact with this feature to escalate their access or bypass intended security controls. The vulnerability is addressed in version 2605_10.2100 or later. The attack requires local access but no user interaction.
Affected products
- Dell ThinOS 10 Versions prior to 2605_10.2100
Timeline
- 2026-07-03: patched: Remediated version 2605_10.2100 released.
- 2026-07-15: advisory: Dell Security Advisory DSA-2026-300 published.
- 2026-07-15: disclosed: CVE-2026-56687 published to NVD.