Junglewise Threat Intelligence

CVE-2026-81467: Dell ThinOS 10 OS command injection

CVE-2026-81467 · Severity: critical · CVSS 9.8 · Published 2026-09-10

Technologies: Dell Pro Rugged 13 Ra13250, Dell Pro Slim Plus Xe5 Oem Qbs1250, Dell ThinOS 10, Dell Latitude 5440, Dell Pro Max 14, Dell Optiplex All-In-One 7410, Dell Pro Tower Qct1250, Dell Latitude 5520, Dell Pro Rugged 14 Rb14250, Dell Wyse 5070 Extended Thin Client, Dell Optiplex All-In-One 7420, Dell Latitude 3330, Dell Pro 24 All-In-One Plus Qb24250, Dell Pro 24 All-In-One \(65w\) Qc24250, Dell Pro 24 All-In-One, Dell Pro Micro Qcm1250, Dell Latitude 3420, Dell Pro Tower Plus Xe5 Oem Qbt1250, Dell Pro 14 Pc14250, Dell Pro Max 16 Plus, Dell Precision 3260 Compact, Dell Latitude 3450, Dell Pro Max Microfcm2250, Dell Optiplex Micro Plus 7010, Dell Latitude 3440, Dell Wyse 5470 Mtc, Dell Pro Micro-Thin Client Q9m1260, Dell ThinOS, Dell Optiplex 7020, Dell Latitude 5540, Dell Latitude 5450, Dell Pro 16 Pc16250, Dell Pro 16 Plus Pb16250, Dell Latitude 5530, Dell Pro Slim Low Sff, Dell Optiplex 3000 Tc, Dell Latitude 5550, Dell Optiplex 5400 All-In-One, Dell Precision 3280, Dell Wyse 5070 Thin Client, Dell Wyse 5470 All-In-One Thin Client. Vendors: Dell.

Executive brief

Dell ThinOS 10 is operating system software used in thin client devices to provide a lightweight computing environment. A flaw in how ThinOS processes user input to operating system commands allows an unauthenticated attacker to inject arbitrary commands remotely, potentially gaining complete control over the device and compromising any systems it connects to.

Technical details

This vulnerability is an OS command injection (CWE-78) in Dell ThinOS 10 prior to version 2605_10.2616, where special elements in user-controlled input are not properly neutralized before being passed to OS command execution functions. An unauthenticated attacker with remote network access can exploit this without authentication or user interaction to execute arbitrary commands with the privileges of the ThinOS process. Successful exploitation allows complete command execution and system compromise. A patch is available in version 2605_10.2616 and later.

Affected products

  • Dell ThinOS 10 prior to 2605_10.2616

Timeline

  • 2026-09-10: disclosed
  • 2026-09-10: patched: Fixed in version 2605_10.2616

References

Related threats