CVE-2026-81467
largeUnauthenticated OS Command Injection RCE in Dell ThinOS 10
Dell ThinOS 10, the operating system for Dell Wyse thin clients, contains an OS command injection flaw (CWE-78) in versions prior to 2605_10.2616, where insufficiently sanitized input passed to an operating system command can be abused by an attacker. An unauthenticated attacker with network access to an affected device can send crafted input to the vulnerable interface and achieve arbitrary command execution on the thin client. Successful exploitation carries maximum impact (CVSS 3.1 9.8, scored with high confidentiality, integrity, and availability impact), potentially giving attackers a foothold in enterprise VDI environments. Any organization running Dell Wyse thin clients on ThinOS 10 below 2605_10.2616 is affected, particularly deployments where management or remote-access services on the devices are reachable from untrusted networks. As of now there is no known exploitation, no public proof-of-concept, and the issue is not listed in CISA's Known Exploited Vulnerabilities catalog.
What to do: Upgrade affected thin clients to ThinOS 10 version 2605_10.2616 or later. Until patched, restrict network access to thin client management and remote-access services so they are not reachable by unauthenticated or untrusted users. Inventory Wyse deployments for ThinOS 10 versions below 2605_10.2616 and monitor for anomalous inbound connections or unexpected processes on those devices.
| Dell ThinOS 10 | all versions prior to 2605_10.2616 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.