Junglewise Threat Intelligence
CVE-2026-81048: Dell ThinOS 10 command injection in adjacent network access
CVE-2026-81048 · Severity: critical · CVSS 9.6 · Published 2026-09-10
Technologies: Dell Pro Rugged 13 Ra13250, Dell Pro Slim Plus Xe5 Oem Qbs1250, Dell ThinOS 10, Dell Latitude 5440, Dell Pro Max 14, Dell Optiplex All-In-One 7410, Dell Pro Tower Qct1250, Dell Latitude 5520, Dell Pro Rugged 14 Rb14250, Dell Wyse 5070 Extended Thin Client, Dell Optiplex All-In-One 7420, Dell Latitude 3330, Dell Pro 24 All-In-One Plus Qb24250, Dell Pro 24 All-In-One \(65w\) Qc24250, Dell Pro 24 All-In-One, Dell Pro Micro Qcm1250, Dell Latitude 3420, Dell Pro Tower Plus Xe5 Oem Qbt1250, Dell Pro 14 Pc14250, Dell Pro Max 16 Plus, Dell Precision 3260 Compact, Dell Latitude 3450, Dell Pro Max Microfcm2250, Dell Optiplex Micro Plus 7010, Dell Latitude 3440, Dell Wyse 5470 Mtc, Dell Pro Micro-Thin Client Q9m1260, Dell ThinOS, Dell Optiplex 7020, Dell Latitude 5540, Dell Latitude 5450, Dell Pro 16 Pc16250, Dell Pro 16 Plus Pb16250, Dell Latitude 5530, Dell Pro Slim Low Sff, Dell Optiplex 3000 Tc, Dell Latitude 5550, Dell Optiplex 5400 All-In-One, Dell Precision 3280, Dell Wyse 5070 Thin Client, Dell Wyse 5470 All-In-One Thin Client. Vendors: Dell.
Executive brief
Dell ThinOS 10 is a thin client operating system used to run lightweight desktop environments on enterprise computers. A command injection vulnerability allows an unauthenticated attacker on the same network segment to execute arbitrary code with elevated privileges on affected devices. This could enable attackers to compromise entire fleets of thin clients, steal data, or establish persistent backdoors across corporate environments.
Technical details
The vulnerability is an improper neutralization of special characters in a command string (CWE-78 command injection). An unauthenticated attacker with adjacent network access (AV:A per CVSS 3.1) can exploit this without authentication (PR:N) or user interaction (UI:N) to achieve remote code execution. The attack scope is changed (S:C), meaning impact extends beyond the vulnerable component to the entire system. No patch bypass or mitigation is described; Dell has issued security update version 2605_10.2616 to remediate this and related vulnerabilities identified in DSA-2026-389.
Affected products
- Dell ThinOS 10 prior to 2605_10.2616