ZeroHour

CVE-2026-81238

moderate

Unauthenticated Access to Critical Functions in Dell Wyse Management Suite

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

Dell Wyse Management Suite versions prior to 2605.0.3.683 fail to require authentication for a critical function (CWE-306), exposing it to the network. An unauthenticated remote attacker who can reach the WMS server can invoke this function directly over the network with no privileges and no user interaction, gaining unauthorized access to the management platform. The CVSS 3.1 vector (7.5, AV:N/AC:L/PR:N/UI:N) confirms easy remote exploitation, but impact is limited to integrity (C:N/I:H/A:N), meaning attackers can modify data, settings, or device-management state without necessarily being able to read it. Organizations running unpatched WMS deployments — which centrally manage fleets of Dell thin clients and endpoints — are affected, with the highest risk to internet-reachable on-premises installs. No public proof-of-concept is known and the flaw is not in CISA's KEV catalog, so no exploitation has been observed.

What to do: Upgrade Dell Wyse Management Suite to version 2605.0.3.683 or later as soon as possible. Until patched, restrict network access to the WMS console and API to trusted internal networks or VPN, since the flaw is remotely exploitable without credentials. Review WMS and reverse-proxy logs for unauthenticated requests and audit managed-device configurations and policies for unauthorized modifications, given the integrity-only impact.

Affected
Dell Wyse Management Suiteprior to 2605.0.3.683
Estimated exposure
moderateroughly 1k-10k on-premises WMS deployments worldwide, of which likely only hundreds of management consoles are internet-exposed — Inferred from enterprise deployment patterns for a niche thin-client management product and typical internet-wide scan counts for WMS consoles; Dell publishes no install counts and no scan data was provided, so this is clearly an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.