Description
Dell ThinOS 10, versions prior to 2605_10.2100, contain an Obsolete Feature in UI vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
Published: 2026-07-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an obsolete feature in the user interface of Dell ThinOS 10. A locally connected attacker with only low privileges can exploit this flaw, potentially gaining unauthorized access. The primary consequence is unapproved use of system resources beyond the attacker’s authorized privileges.

Affected Systems

Dell ThinOS 10, versions earlier than 2605_10.2100, are affected. This includes all installations of ThinOS 10 prior to the release identified by the reference advisory.

Risk and Exploitability

With a CVSS score of 7.8, the vulnerability is considered high severity. The EPSS score of less than 1% indicates that the probability of exploitation is currently very low, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local, requiring physical or privileged network access. Given the low exploitation probability but substantial impact, systems should still be updated promptly to mitigate the risk.

Generated by OpenCVE AI on July 31, 2026 at 03:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dell ThinOS 10 to version 2605_10.2100 or later using the Dell security update available at the provided DellKB link.
  • Disable or remove the obsolete UI feature through configuration or disablement settings, if available, to prevent its use by local users.
  • Enforce strict local access controls, such as least privilege authentication and role‑based access control, to limit the ability of low‑privileged users to interact with the UI.

Generated by OpenCVE AI on July 31, 2026 at 03:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Obsolete UI Feature Enables Unauthorized Local Access in Dell ThinOS 10

Thu, 30 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell thinos
Vendors & Products Dell
Dell thinos

Fri, 24 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Local Exploit of Obsolete UI Feature in Dell ThinOS 10 Leads to Unauthorized Access

Fri, 17 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Local Exploit of Obsolete UI Feature in Dell ThinOS 10 Leads to Unauthorized Access

Wed, 15 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Description Dell ThinOS 10, versions prior to 2605_10.2100, contain an Obsolete Feature in UI vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
Weaknesses CWE-448
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-07-16T03:55:52.361Z

Reserved: 2026-06-22T17:04:26.238Z

Link: CVE-2026-56687

cve-icon Vulnrichment

Updated: 2026-07-15T19:22:01.003Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T03:15:04Z

Weaknesses