Executive brief
Dell ThinOS 10 is a thin client operating system used in enterprise environments to provide secure remote desktop access. A low-privileged attacker with local access to an affected system can bypass access controls to gain unauthorized system access, potentially compromising confidential information and allowing unauthorized modifications to the device or network.
Technical details
This vulnerability is an improper access control flaw in the proprietary code of Dell ThinOS 10 versions prior to 2605_10.2518. The vulnerability requires local access and low privilege credentials to exploit, with no user interaction needed. An attacker meeting these preconditions can bypass access controls to achieve unauthorized access with high impact to confidentiality, integrity, and availability (CIA triad). A patch is available in version 2605_10.2518 and later.
Affected products
- Dell ThinOS 10 prior to 2605_10.2518
Timeline
- 2026-08-24: disclosed