ZeroHour

CVE-2026-81239

moderate

Unauthenticated File Upload RCE in Dell Wyse Management Suite

CVSS 3.1
8.6 high
EPSS
Published
()
Modified
AI analysis

Dell Wyse Management Suite versions prior to 2605.0.3.683 contain an unrestricted upload of file with dangerous type flaw (CWE-434) that allows an unauthenticated, remotely connected attacker to upload a malicious file to the application. Successful exploitation can lead to remote code execution on the management server, with high impact to integrity and limited impact to confidentiality and availability (CVSS 3.1: 8.6). This is especially serious because the suite centrally manages fleets of Dell Wyse thin clients, so a compromised server could become a pivot point for broader endpoint compromise. Organizations running on-premises or self-managed deployments of Wyse Management Suite before 2605.0.3.683 are affected. No public proof-of-concept exists and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog.

What to do: Upgrade Dell Wyse Management Suite to version 2605.0.3.683 or later as soon as possible. Until patched, restrict access to the WMS console so it is reachable only from trusted management networks or a VPN, and monitor server logs and upload directories for unexpected file uploads or anomalous process execution originating from the application account.

Affected
Dell Wyse Management Suiteprior to 2605.0.3.683 (< 2605.0.3.683)
Estimated exposure
moderate≈ hundreds to low thousands of internet-exposed WMS consoles out of an estimated several thousand enterprise deployments (estimate) — Wyse Management Suite is an enterprise thin-client management platform typically deployed one-per-organization (on-premises or self-hosted cloud), and management consoles of this class generally show low-thousands or fewer…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L

In the news

No ingested article mentions this CVE yet.