Description
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Incorrect Default Permission vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.
Published: 2026-08-14
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell Wyse Management Suite (WMS) versions before 2605.0.2 contain an incorrect default permission that permits a low‑privileged local user to elevate their privileges, potentially granting full system control. The flaw is classified as CWE-269 and has a CVSS score of 7.8, indicating a high likelihood of a significant impact if exploited.

Affected Systems

The vulnerability applies to Dell Wyse Management Suite (WMS) installations running any version earlier than 2605.0.2. Local accounts that retain the default permissions are at risk.

Risk and Exploitability

The high CVSS score reflects serious risk, even though EPSS is not available and the vulnerability is not yet listed in the CISA KEV catalog. An attacker would need only local access with low privileges, making exploitation straightforward. Successful exploitation results in privilege escalation that can compromise the entire system.

Generated by OpenCVE AI on August 14, 2026 at 17:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Dell Wyse Management Suite to version 2605.0.2 or later, which removes the incorrect default permissions.
  • Review and enforce least‑privilege for all local user accounts, ensuring standard users do not possess administrative rights.
  • Verify that new user accounts are created with restricted permissions and that no custom accounts inherit elevated privileges.

Generated by OpenCVE AI on August 14, 2026 at 17:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Description Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Incorrect Default Permission vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-14T16:47:15.560Z

Reserved: 2026-07-17T17:05:09.170Z

Link: CVE-2026-63700

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-14T16:16:58.553

Modified: 2026-08-14T17:19:46.210

Link: CVE-2026-63700

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T17:45:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management