ZeroHour

CVE-2026-81236

moderate

Unauthenticated File Upload RCE in Dell Wyse Management Suite

CVSS 3.1
8.6 high
EPSS
Published
()
Modified
AI analysis

Dell Wyse Management Suite (WMS) versions prior to 2605.0.3.683 contain an unrestricted upload of file with dangerous type flaw (CWE-434) rated CVSS 3.1 8.6 (high). An unauthenticated remote attacker can upload a maliciously crafted file to the WMS server and achieve remote code execution, with high impact on integrity and low impact on confidentiality and availability. Exploitation requires only network access to the management suite with no privileges or user interaction, making internet-reachable WMS consoles especially attractive targets. Successful compromise of WMS could allow an attacker to pivot to the fleets of thin clients and endpoints the platform manages. No public proof-of-concept is known and the flaw is not on the CISA KEV list.

What to do: Upgrade Dell Wyse Management Suite to version 2605.0.3.683 or later as soon as possible. Until patched, restrict network access to the WMS console (VPN or allowlist) so it is not reachable from the unauthenticated internet, and monitor upload directories and server logs for unexpected files or webshell indicators dating back to before the fix. Also verify the integrity of thin-client management policies and deployment packages for signs of post-compromise tampering.

Affected
Dell Wyse Management Suiteversions prior to 2605.0.3.683
Estimated exposure
moderatelikely low thousands of WMS installations worldwide, each potentially managing fleets of thin clients — WMS is an enterprise thin-client management console typically deployed once per organization (on-premises or private cloud), so the server footprint is small while each deployment can indirectly govern thousands of managed endpoints; no…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L

In the news

No ingested article mentions this CVE yet.