Description
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.
Published: 2026-08-14
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an Unrestricted Upload of Dangerous Type that allows an attacker with high privileged remote access to upload a malicious file and have it executed by the server, resulting in Remote Code Execution. This flaw grants the attacker the same privileges as the application, enabling full compromise of the affected system. The weakness is categorized as CWE-434.

Affected Systems

Dell Wyse Management Suite (Dell:Wyse Management Suite), versions prior to 2605.0.2, are affected. These systems are typically deployed in enterprise environments for device management and are listed as the sole impacted vendor and product. No other vendors or versions are cited.

Risk and Exploitability

The CVSS score of 7.2 reflects a medium to high severity. EPSS is not available, so the exploitation probability is unknown, and the vulnerability is not listed in CISA's KEV catalog. The attack requires remote access with high privileges, such as an administrator, and can be performed via the web interface that accepts file uploads.

Generated by OpenCVE AI on August 14, 2026 at 16:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Dell Wyse Management Suite update that brings the product to version 2605.0.2 or later.
  • Reconfigure the WMS server to restrict or disable the file‑upload function for non‑essential users and allow only safe file types.
  • Enable logging and continuous monitoring of upload activities to detect anomalous behavior.

Generated by OpenCVE AI on August 14, 2026 at 16:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:dell:wyse_management_suite:*:*:*:*:*:*:*:*

Mon, 17 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell wyse Management Suite
Vendors & Products Dell
Dell wyse Management Suite

Sat, 15 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 14 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Unrestricted File Upload Leading to Remote Code Execution in Dell Wyse Management Suite

Fri, 14 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Description Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Wyse Management Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-15T03:55:45.294Z

Reserved: 2026-07-24T11:04:27.160Z

Link: CVE-2026-66270

cve-icon Vulnrichment

Updated: 2026-08-14T16:08:42.766Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-14T16:16:58.913

Modified: 2026-08-17T18:38:37.470

Link: CVE-2026-66270

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T11:01:09Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type