Junglewise Threat Intelligence
CVE-2026-81052: Dell ThinOS 10 code integrity check bypass
CVE-2026-81052 · Severity: medium · CVSS 6.8 · Published 2026-09-10
Technologies: Dell Pro Rugged 13 Ra13250, Dell Pro Slim Plus Xe5 Oem Qbs1250, Dell ThinOS 10, Dell Latitude 5440, Dell Pro Max 14, Dell Optiplex All-In-One 7410, Dell Pro Tower Qct1250, Dell Latitude 5520, Dell Pro Rugged 14 Rb14250, Dell Wyse 5070 Extended Thin Client, Dell Optiplex All-In-One 7420, Dell Latitude 3330, Dell Pro 24 All-In-One Plus Qb24250, Dell Pro 24 All-In-One \(65w\) Qc24250, Dell Pro 24 All-In-One, Dell Pro Micro Qcm1250, Dell Latitude 3420, Dell Pro Tower Plus Xe5 Oem Qbt1250, Dell Pro 14 Pc14250, Dell Pro Max 16 Plus, Dell Precision 3260 Compact, Dell Latitude 3450, Dell Pro Max Microfcm2250, Dell Optiplex Micro Plus 7010, Dell Latitude 3440, Dell Wyse 5470 Mtc, Dell Pro Micro-Thin Client Q9m1260, Dell ThinOS, Dell Optiplex 7020, Dell Latitude 5540, Dell Latitude 5450, Dell Pro 16 Pc16250, Dell Pro 16 Plus Pb16250, Dell Latitude 5530, Dell Pro Slim Low Sff, Dell Optiplex 3000 Tc, Dell Latitude 5550, Dell Optiplex 5400 All-In-One, Dell Precision 3280, Dell Wyse 5070 Thin Client, Dell Wyse 5470 All-In-One Thin Client. Vendors: Dell.
Executive brief
Dell ThinOS 10 is an operating system used in thin client devices that provide remote desktop access to corporate networks. This vulnerability allows an unauthenticated attacker with physical access to the device to download and execute arbitrary code without verification, potentially taking full control of the thin client and compromising the systems it connects to.
Technical details
The vulnerability is a Download of Code Without Integrity Check flaw (CWE-494) in Dell ThinOS 10 versions prior to 2605_10.2616. An unauthenticated attacker with physical access can exploit this to download and execute malicious code without proper cryptographic verification. The attack vector is physical, requiring direct access to the device, and results in arbitrary code execution with system privileges. Patches are available in version 2605_10.2616 and later.
Affected products
- Dell ThinOS 10 prior to 2605_10.2616
Timeline
- 2026-09-10: disclosed
- 2026-09-10: patched: Fixed in version 2605_10.2616