CVE-2026-81468
largeOS Command Injection in Dell ThinOS 10 allows privileged remote command execution
CVE-2026-81468 is an OS command injection flaw (CWE-78) in Dell ThinOS 10, the operating system used on Dell Wyse enterprise thin clients, affecting versions prior to 2605_10.2616. A remote attacker who has already obtained high-level privileges can submit input containing special shell elements that ThinOS fails to properly neutralize, causing arbitrary operating system commands to be executed on the device. Because the CVSS scope is changed with high impact to confidentiality, integrity and availability, a successful attack is rated critical (9.1) and could compromise the thin client and potentially adjacent managed components. Organizations running Dell Wyse thin clients on ThinOS 10 are affected, particularly where remote administrative access to devices or management infrastructure is possible. There is currently no known exploitation: the flaw is not in CISA's KEV catalog and no public proof-of-concept is known.
What to do: Upgrade affected devices to ThinOS 10 version 2605_10.2616 or later, typically via Wyse Management Suite or your standard thin client imaging process. In the meantime, restrict remote administrative access to ThinOS 10 devices and the management infrastructure, review whether highly privileged accounts or admin interfaces could be reachable by untrusted networks, and check management logs for unexpected administrative activity. Monitor Dell security advisories for updates, as this flaw is assigned and maintained by Dell's PSIRT (CNA: [email protected]).
| Dell ThinOS 10 | all versions prior to 2605_10.2616 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.