ZeroHour

CVE-2026-81046

large

Unauthenticated Arbitrary Code Execution in Dell ThinOS 10

CVSS 3.1
9.4 critical
EPSS
Published
()
Modified
AI analysis

Dell ThinOS 10, in versions prior to 2605_10.2616, contains a Protection Mechanism Failure (CWE-284) that allows an intended security protection to be bypassed. According to Dell, an unauthenticated attacker with remote network access to an affected thin client could trigger the flaw, requiring no privileges or user interaction. Successful exploitation leads to arbitrary code execution within the application context, with high confidentiality and integrity impact and low availability impact per the CVSS vector. Affected organizations are those running Dell Wyse thin clients on ThinOS 10 builds older than 2605_10.2616. There is currently no public proof-of-concept, the flaw is not listed in CISA's KEV catalog, and no confirmed in-the-wild exploitation is known, but the critical 9.4 CVSS score warrants prompt patching.

What to do: Upgrade affected Dell Wyse thin clients to ThinOS 10 version 2605_10.2616 or later as directed by Dell's advisory. In the interim, inventory your fleet for ThinOS 10 devices and limit remote network access to them (e.g., via network segmentation) since exploitation requires no authentication or user interaction. Monitor Dell's advisory for updates, as no public PoC or KEV listing exists yet.

Affected
Dell ThinOS 10all versions prior to 2605_10.2616
Estimated exposure
largelikely hundreds of thousands of thin-client endpoints (exact ThinOS 10 installed base not publicly disclosed) — Dell Wyse has historically been the dominant thin-client line in enterprise VDI estates with tens of millions of units shipped cumulatively, so the current-generation ThinOS 10 fleet plausibly reaches six figures, though most devices sit…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Arbitrary Code Execution within the application context.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

In the news

No ingested article mentions this CVE yet.