Description
Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
Published: 2026-08-24
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access via Improper Access Control
Action: Apply Patch
AI Analysis

Impact

Dell ThinOS 10 contains an Improper Access Control flaw that allows a user with low privileges and local access to gain unauthorized access to the system. The vulnerability can be leveraged to bypass intended access restrictions, potentially enabling a user to execute privileged commands or read sensitive data without proper authorization. This impact affects the confidentiality and integrity of the system as the attacker may manipulate or retrieve protected information.

Affected Systems

The affected product is Dell ThinOS 10, specifically all releases prior to version 2605_10.2518. Only these older builds are vulnerable; later releases contain the fix.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that exploitation may not yet be widespread. The attack vector described is a low‑privileged local attacker, implying the attacker must have physical or local network access to the device. Once the flaw is triggered, the attacker can gain unauthorized control within the scope of the compromised system.

Generated by OpenCVE AI on August 24, 2026 at 20:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update ThinOS to version 2605_10.2518 or later
  • Enforce least‑privilege on user accounts and disable unused services
  • Monitor audit logs and audit configuration changes for evidence of privilege escalation

Generated by OpenCVE AI on August 24, 2026 at 20:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell thinos
CPEs cpe:2.3:o:dell:thinos:*:*:*:*:*:*:*:*
Vendors & Products Dell
Dell thinos

Thu, 27 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Dell ThinOS 10 Leading to Unauthorized Access

Mon, 24 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-27T16:24:50.370Z

Reserved: 2026-07-09T11:05:01.707Z

Link: CVE-2026-61419

cve-icon Vulnrichment

Updated: 2026-08-27T16:14:59.520Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-24T20:16:51.990

Modified: 2026-09-02T18:20:51.960

Link: CVE-2026-61419

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T20:30:07Z

Weaknesses