Description
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.
Published: 2026-08-14
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an Unrestricted Upload of Dangerous Type that allows an attacker with high privileged remote access to upload a malicious file and have it executed by the server, resulting in Remote Code Execution. This flaw grants the attacker the same privileges as the application, enabling full compromise of the affected system. The weakness is categorized as CWE-434.

Affected Systems

Dell Wyse Management Suite (Dell:Wyse Management Suite), versions prior to 2605.0.2, are affected. These systems are typically deployed in enterprise environments for device management and are listed as the sole impacted vendor and product. No other vendors or versions are cited.

Risk and Exploitability

The CVSS score of 7.2 reflects a medium to high severity. EPSS is not available, so the exploitation probability is unknown, and the vulnerability is not listed in CISA's KEV catalog. The attack requires remote access with high privileges, such as an administrator, and can be performed via the web interface that accepts file uploads.

Generated by OpenCVE AI on August 14, 2026 at 16:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Dell Wyse Management Suite update that brings the product to version 2605.0.2 or later.
  • Reconfigure the WMS server to restrict or disable the file‑upload function for non‑essential users and allow only safe file types.
  • Enable logging and continuous monitoring of upload activities to detect anomalous behavior.

Generated by OpenCVE AI on August 14, 2026 at 16:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Unrestricted File Upload Leading to Remote Code Execution in Dell Wyse Management Suite

Fri, 14 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Description Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-14T16:08:47.105Z

Reserved: 2026-07-24T11:04:27.160Z

Link: CVE-2026-66270

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-14T16:16:58.913

Modified: 2026-08-14T16:16:58.913

Link: CVE-2026-66270

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T16:30:05Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type