ZeroHour

CVE-2026-81468

large

OS Command Injection in Dell ThinOS 10 allows privileged remote command execution

CVSS 3.1
9.1 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-81468 is an OS command injection flaw (CWE-78) in Dell ThinOS 10, the operating system used on Dell Wyse enterprise thin clients, affecting versions prior to 2605_10.2616. A remote attacker who has already obtained high-level privileges can submit input containing special shell elements that ThinOS fails to properly neutralize, causing arbitrary operating system commands to be executed on the device. Because the CVSS scope is changed with high impact to confidentiality, integrity and availability, a successful attack is rated critical (9.1) and could compromise the thin client and potentially adjacent managed components. Organizations running Dell Wyse thin clients on ThinOS 10 are affected, particularly where remote administrative access to devices or management infrastructure is possible. There is currently no known exploitation: the flaw is not in CISA's KEV catalog and no public proof-of-concept is known.

What to do: Upgrade affected devices to ThinOS 10 version 2605_10.2616 or later, typically via Wyse Management Suite or your standard thin client imaging process. In the meantime, restrict remote administrative access to ThinOS 10 devices and the management infrastructure, review whether highly privileged accounts or admin interfaces could be reachable by untrusted networks, and check management logs for unexpected administrative activity. Monitor Dell security advisories for updates, as this flaw is assigned and maintained by Dell's PSIRT (CNA: [email protected]).

Affected
Dell ThinOS 10all versions prior to 2605_10.2616
Estimated exposure
largelikely on the order of 100,000s of Dell Wyse thin clients running ThinOS 10 in enterprise and VDI fleets (exact published counts unavailable) — Dell Wyse is a market-leading thin client line with a multi-million-unit cumulative installed base, and ThinOS 10 is its current-generation OS widely deployed in enterprise VDI environments, making a six-figure device count a plausible…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.

Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.