CVE-2026-81240
moderateUnauthenticated File Upload RCE in Dell Wyse Management Suite
Dell Wyse Management Suite versions prior to 2605.0.3.683 contain an unrestricted upload of file with dangerous type flaw (CWE-434) that allows an unauthenticated, remote attacker to upload a malicious file and achieve remote code execution on the management server. The flaw is triggered by sending a crafted file upload request to an accessible WMS endpoint, requiring no valid credentials or user interaction. Successful exploitation gives the attacker code execution on the suite's server with high impact to integrity and lower impact to confidentiality and availability (CVSS 3.1: 8.6). Any organization running an on-premises Wyse Management Suite deployment older than 2605.0.3.683 is affected, with the highest risk to instances reachable from untrusted networks such as the internet. There is no evidence of in-the-wild exploitation and no public proof of concept is known, but the unauthenticated and pre-auth-RCE nature makes patching urgent.
What to do: Upgrade Dell Wyse Management Suite to version 2605.0.3.683 or later as soon as possible. Until patched, restrict network access to the WMS console (VPN or allowlisted IP ranges) and avoid exposing it to the internet. Review server logs and uploaded-file directories for unexpected files or upload activity from unauthenticated sources that could indicate attempted exploitation.
| Dell Wyse Management Suite | prior to 2605.0.3.683 (< 2605.0.3.683) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
- Weakness
- CWE-434
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
In the news0 stories
No ingested article mentions this CVE yet.