Junglewise Threat Intelligence

CVE-2026-56687: Dell ThinOS 10 obsolete feature in UI unauthorized access

CVE-2026-56687 · Severity: high · CVSS 7.8 · Published 2026-07-15

Technologies: Dell ThinOS 10, Dell ThinOS. Vendors: Dell.

Executive brief

Dell ThinOS 10, an operating system used in thin client devices for secure cloud and VDI access, contains a vulnerability where an obsolete user interface feature remains accessible. A user with low-level access to the device could exploit this legacy feature to gain unauthorized access to the system. This could potentially allow an attacker to bypass security restrictions or access sensitive information on the local terminal.

Technical details

Dell ThinOS 10 is affected by an 'Obsolete Feature in UI' vulnerability (CWE-448). The flaw exists because a legacy or deprecated feature remains present in the user interface, providing a path for unauthorized actions. A local attacker with low privileges can interact with this feature to escalate their access or bypass intended security controls. The vulnerability is addressed in version 2605_10.2100 or later. The attack requires local access but no user interaction.

Affected products

  • Dell ThinOS 10 Versions prior to 2605_10.2100

Timeline

  • 2026-07-03: patched: Remediated version 2605_10.2100 released.
  • 2026-07-15: advisory: Dell Security Advisory DSA-2026-300 published.
  • 2026-07-15: disclosed: CVE-2026-56687 published to NVD.

References

Related threats