Executive brief
Dell Wyse Management Suite is a centralized management platform for Wyse thin clients and endpoints used in enterprise environments. A missing authentication vulnerability allows unauthenticated attackers with network access to bypass security controls and gain unauthorized access to critical administrative functions, potentially compromising the entire managed infrastructure.
Technical details
CVE-2026-81238 is a missing authentication vulnerability in Dell Wyse Management Suite versions prior to 2605.0.3.683, classified as a critical function authentication bypass. An unauthenticated attacker with network-level access can exploit this vulnerability without requiring valid credentials or user interaction. The flaw allows direct access to sensitive administrative operations, leading to unauthorized modifications and system compromise. The vulnerability has a CVSS 3.1 base score of 7.5 with network attack vector and no privilege requirements. A patch is available in version 2605.0.3.683 or later.
Affected products
- Dell Wyse Management Suite prior to 2605.0.3.683
Timeline
- 2026-09-15: disclosed
- 2026-09-15: advisory