Executive brief
Dell Wyse Management Suite is a centralized management platform for thin client devices used in enterprise environments. An unauthenticated remote attacker can upload malicious files to the system without proper validation, potentially achieving remote code execution and full system compromise. This vulnerability requires no user authentication or interaction, making it immediately exploitable over the network.
Technical details
The vulnerability is a classic unrestricted file upload flaw with dangerous type handling in Dell Wyse Management Suite versions before 2605.0.3.683. The vulnerability allows unauthenticated remote attackers (network reachable) to upload files of dangerous types (such as executables or scripts) without proper validation or filtering. By uploading and triggering execution of malicious files, an attacker can achieve remote code execution with the privileges of the management suite process, potentially leading to full system compromise. The attack vector is network-based with low attack complexity and no authentication required. Patched versions (2605.0.3.683 and later) are available from Dell.
Affected products
- Dell Wyse Management Suite prior to 2605.0.3.683
Timeline
- 2026-09-15: disclosed: CVE-2026-81240 published