Junglewise Threat Intelligence

CVE-2026-81236: Dell Wyse Management Suite unrestricted file upload

CVE-2026-81236 · Severity: high · CVSS 8.6 · Published 2026-09-15

Executive brief

Dell Wyse Management Suite is an administrative tool used to manage and monitor thin client devices across organizations. An unauthenticated attacker can upload malicious files to the system from the network, potentially executing arbitrary code and compromising the entire management infrastructure and any connected devices.

Technical details

Dell Wyse Management Suite versions prior to 2605.0.3.683 contain an unrestricted file upload vulnerability (CWE-434) that accepts dangerous file types without proper validation or authentication. An unauthenticated remote attacker with network access can exploit this flaw via an upload function, leading to arbitrary code execution with the privileges of the management suite process. The vulnerability is exploitable over the network without user interaction or authentication, making it directly accessible to external attackers. A patch is available in version 2605.0.3.683 and later.

Affected products

  • Dell Wyse Management Suite prior to 2605.0.3.683

Timeline

  • 2026-09-15: disclosed

References

Related threats