Description
Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Link Resolution Before File Access vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
Published: 2026-06-22
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper link resolution before file access flaw in Dell Wyse Management Suite (WMS). An attacker with only low local privileges can craft a request that resolves maliciously constructed links, allowing the WMS component to read, delete, or overwrite files that the attacker is not authorized to access. Because the flaw lies in path resolution, it can be exploited by calling operations that resolve directory references that bypass normal security checks, leading to unauthorized information disclosure or modification of system files. The weakness is identified as CWE‑59, which indicates a path manipulation issue that can directly compromise confidentiality and integrity of data on the targeted device.

Affected Systems

Dell Wyse Management Suite (WMS) versions prior to 2605 are affected. Any instance of WMS that has not been upgraded beyond version 2605 exposes users to this risk.

Risk and Exploitability

The CVSS score is 7.8, indicating a high severity. The EPSS score is not available, so the precise exploitation probability cannot be quantified, but the flaw has a moderate to high risk of exploitation because it requires only local access and no elevated privileges. The vulnerability is not included in the CISA KEV catalog, which suggests that it has not yet been widely exploited in the wild. Nevertheless, the local authorized attacker can achieve unauthorized file access, which could provide a foothold for further compromise if additional privileges exist on the system. The likely attack vector is local; the attacker must be able to access the WMS process on the host to trigger the link resolution flaw.

Generated by OpenCVE AI on June 22, 2026 at 21:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dell Wyse Management Suite to version 2605 or later.
  • Restrict the WMS service or process to the minimal set of file system permissions required for normal operation, ensuring that it does not have read or write access to sensitive directories.
  • Disable or remove local user accounts that can launch the WMS management console or processes unless they are strictly necessary for legitimate business purposes.

Generated by OpenCVE AI on June 22, 2026 at 21:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 22 Jun 2026 21:45:00 +0000

Type Values Removed Values Added
Title WMS Improper Link Resolution Enables Local Unauthorized File Access

Mon, 22 Jun 2026 20:00:00 +0000

Type Values Removed Values Added
Description Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Link Resolution Before File Access vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
Weaknesses CWE-59
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-06-22T18:47:43.198Z

Reserved: 2026-05-05T17:04:45.714Z

Link: CVE-2026-44274

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-22T21:30:06Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')