CVE-2026-81046
largeUnauthenticated Arbitrary Code Execution in Dell ThinOS 10
Dell ThinOS 10, in versions prior to 2605_10.2616, contains a Protection Mechanism Failure (CWE-284) that allows an intended security protection to be bypassed. According to Dell, an unauthenticated attacker with remote network access to an affected thin client could trigger the flaw, requiring no privileges or user interaction. Successful exploitation leads to arbitrary code execution within the application context, with high confidentiality and integrity impact and low availability impact per the CVSS vector. Affected organizations are those running Dell Wyse thin clients on ThinOS 10 builds older than 2605_10.2616. There is currently no public proof-of-concept, the flaw is not listed in CISA's KEV catalog, and no confirmed in-the-wild exploitation is known, but the critical 9.4 CVSS score warrants prompt patching.
What to do: Upgrade affected Dell Wyse thin clients to ThinOS 10 version 2605_10.2616 or later as directed by Dell's advisory. In the interim, inventory your fleet for ThinOS 10 devices and limit remote network access to them (e.g., via network segmentation) since exploitation requires no authentication or user interaction. Monitor Dell's advisory for updates, as no public PoC or KEV listing exists yet.
| Dell ThinOS 10 | all versions prior to 2605_10.2616 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Arbitrary Code Execution within the application context.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
In the news0 stories
No ingested article mentions this CVE yet.