Junglewise Threat Intelligence

CVE-2026-81239: Dell Wyse Management Suite unrestricted file upload

CVE-2026-81239 · Severity: high · CVSS 8.6 · Published 2026-09-15

Executive brief

Dell Wyse Management Suite is a remote management platform used to administer Dell thin client devices across enterprise networks. An unauthenticated attacker can upload malicious files to vulnerable versions, leading to complete remote code execution on the management server. This exposes all managed endpoints and stored credentials to compromise.

Technical details

The vulnerability is an unrestricted file upload with dangerous type validation (CWE-434), affecting Dell Wyse Management Suite versions prior to 2605.0.3.683. An unauthenticated attacker with network access can upload executable files without proper validation, bypassing file type checks. No authentication is required, and the attack can be executed remotely over the network without user interaction. Successful exploitation leads to arbitrary remote code execution on the management server. A patch is available in version 2605.0.3.683 and later.

Affected products

  • Dell Wyse Management Suite prior to 2605.0.3.683

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: advisory

References

Related threats