Description
Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.
Published: 2026-06-25
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Dell Wyse Management Suite contains an improper limitation of a pathname to a restricted directory vulnerability that can be leveraged by an attacker with high privileges to execute arbitrary code on the host. The weakness is a classic path‑traversal flaw (CWE‑22) that arises when untrusted input is resolved to a file location without sufficiently constraining the path. A successful exploitation could compromise the confidentiality, integrity, and availability of the managed systems, potentially allowing a remote attacker to install malware or perform further lateral movement within the environment.

Affected Systems

This issue affects all Dell Wyse Management Suite releases prior to version 5.5 HF1. Systems running earlier builds are vulnerable; newer releases (starting with 5.5 HF1) contain the remediation. Only the WMS product is listed, and no additional affected vendors or products are identified.

Risk and Exploitability

The vulnerability has a CVSS score of 7.2, indicating a high severity. The EPSS score is currently unavailable, so an exact exploitation probability cannot be quantified, but the absence of a low EPSS score suggests that the risk profile relies heavily on the presence of a high‑privileged remote attacker. The vulnerability is not listed in CISA’s KEV catalog. An attacker that can connect remotely to the Management Suite and possesses elevated privileges could exploit the path traversal to execute code, as described in the advisory. No known public exploits are reported, but the potential remains if configuration or privilege controls are lax.

Generated by OpenCVE AI on June 25, 2026 at 15:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell Wyse Management Suite update to version 5.5 HF1 or later to remove the path traversal vulnerability.
  • Limit remote management access to trusted networks or VPN segments, ensuring only authorized administrators can reach the WMS deployment.
  • Configure file system permissions on the WMS host to restrict write access to the directories used by the application, preventing unauthorized file creation or overwrite.

Generated by OpenCVE AI on June 25, 2026 at 15:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 25 Jun 2026 16:15:00 +0000

Type Values Removed Values Added
Title Dell Wyse Management Suite Path Traversal Allowing Remote Code Execution

Thu, 25 Jun 2026 14:00:00 +0000

Type Values Removed Values Added
Description Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-06-25T13:23:58.069Z

Reserved: 2026-05-31T17:04:24.517Z

Link: CVE-2026-49506

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-25T16:00:12Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')