Junglewise Threat Intelligence
CVE-2026-81051: Dell ThinOS 10 security version number bypass
CVE-2026-81051 · Severity: medium · CVSS 6.6 · Published 2026-09-10
Technologies: Dell Latitude 5440, Dell Wyse 5070 Thin Client, Dell Optiplex 3000 Tc, Dell Latitude 3440, Dell Pro 16 Pc16250, Dell Optiplex 7020, Dell Pro Micro Qcm1250, Dell Pro 24 All-In-One Plus Qb24250, Dell Optiplex All-In-One 7420, Dell Pro 14 Pc14250, Dell Latitude 5520, Dell ThinOS 10, Dell Wyse 5470 All-In-One Thin Client, Dell Pro Rugged 14 Rb14250, Dell Precision 3260 Compact, Dell Pro Max Microfcm2250, Dell Pro Rugged 13 Ra13250, Dell Pro Max 14, Dell Latitude 5550, Dell Latitude 3420, Dell Pro Tower Qct1250, Dell Precision 3280, Dell Optiplex Micro Plus 7010, Dell Wyse 5470 Mtc, Dell Optiplex All-In-One 7410, Dell Latitude 3450, Dell Pro Max 16 Plus, Dell Pro Micro-Thin Client Q9m1260, Dell ThinOS, Dell Latitude 5540, Dell Latitude 3330, Dell Pro 24 All-In-One \(65w\) Qc24250, Dell Pro 16 Plus Pb16250, Dell Latitude 5530, Dell Pro 24 All-In-One, Dell Optiplex 5400 All-In-One, Dell Wyse 5070 Extended Thin Client, Dell Pro Tower Plus Xe5 Oem Qbt1250, Dell Pro Slim Low Sff, Dell Pro Slim Plus Xe5 Oem Qbs1250, Dell Latitude 5450. Vendors: Dell.
Executive brief
Dell ThinOS 10 is a thin client operating system used to power lightweight workstations in enterprise environments. CVE-2026-81051 is a vulnerability that allows an attacker with physical access and low privilege to downgrade the security version number, bypassing firmware integrity protections. An attacker could exploit this to roll back security patches and enable further compromise of the device.
Technical details
This vulnerability involves improper security version number validation that permits downgrade to older firmware versions. An attacker with low privilege and physical access to the device can modify or manipulate the security version number mechanism, bypassing the protection that normally prevents installation of older, potentially vulnerable firmware. The attack requires local physical interaction with the device but no elevated privileges, and leads to circumvention of security controls that would normally reject older firmware. Dell has addressed this issue in ThinOS 10 version 2605_10.2616 and later.
Affected products
- Dell ThinOS 10 prior to 2605_10.2616