Junglewise Threat Intelligence
CVE-2026-81046: Dell ThinOS 10 protection mechanism failure remote code execution
CVE-2026-81046 · Severity: critical · CVSS 9.4 · Published 2026-09-10
Technologies: Dell Latitude 5440, Dell Wyse 5070 Thin Client, Dell Optiplex 3000 Tc, Dell Latitude 3440, Dell Pro 16 Pc16250, Dell Optiplex 7020, Dell Pro Micro Qcm1250, Dell Pro 24 All-In-One Plus Qb24250, Dell Optiplex All-In-One 7420, Dell Pro 14 Pc14250, Dell Latitude 5520, Dell ThinOS 10, Dell Wyse 5470 All-In-One Thin Client, Dell Pro Rugged 14 Rb14250, Dell Precision 3260 Compact, Dell Pro Max Microfcm2250, Dell Pro Rugged 13 Ra13250, Dell Pro Max 14, Dell Latitude 5550, Dell Latitude 3420, Dell Pro Tower Qct1250, Dell Precision 3280, Dell Optiplex Micro Plus 7010, Dell Wyse 5470 Mtc, Dell Optiplex All-In-One 7410, Dell Latitude 3450, Dell Pro Max 16 Plus, Dell Pro Micro-Thin Client Q9m1260, Dell ThinOS, Dell Latitude 5540, Dell Latitude 3330, Dell Pro 24 All-In-One \(65w\) Qc24250, Dell Pro 16 Plus Pb16250, Dell Latitude 5530, Dell Pro 24 All-In-One, Dell Optiplex 5400 All-In-One, Dell Wyse 5070 Extended Thin Client, Dell Pro Tower Plus Xe5 Oem Qbt1250, Dell Pro Slim Low Sff, Dell Pro Slim Plus Xe5 Oem Qbs1250, Dell Latitude 5450. Vendors: Dell.
Executive brief
Dell ThinOS 10 is an operating system used in Dell thin client devices that connect to enterprise computing resources. A protection mechanism failure in versions prior to 2605_10.2616 allows remote attackers to execute arbitrary code without authentication, potentially compromising the device and gaining access to sensitive corporate network resources and data.
Technical details
This vulnerability is a protection mechanism failure in Dell ThinOS 10 that allows unauthenticated remote code execution. The flaw resides in proprietary Dell code and requires no user interaction or special preconditions; attackers on the network can directly exploit it. The vulnerability permits arbitrary code execution within the application context, which may allow further system compromise. Versions prior to 2605_10.2616 are affected; patched versions are available from Dell.
Affected products
- Dell ThinOS 10 prior to 2605_10.2616
Timeline
- 2026-09-10: disclosed
- 2026-09-10: patched: Version 2605_10.2616 and later contain the fix