Description
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.
Published: 2026-08-14
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell Wyse Management Suite versions prior to 2605.0.2 contain an unrestricted file upload flaw that allows a high‑privileged remote attacker to upload files of dangerous types. The vulnerability falls under CWE‑434 and can lead to direct remote code execution on the affected system if the attacker succeeds in uploading a malicious payload. The impact is broad, potentially affecting system confidentiality, integrity, and availability as the attacker gains the ability to run arbitrary code on the server.

Affected Systems

The affected product is Dell Wyse Management Suite (WMS) for all versions earlier than 2605.0.2.

Risk and Exploitability

The CVSS score is 7.2, indicating a high severity. No EPSS score is published, so the likelihood of exploitation is currently unknown. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote, requiring high‑privileged access, as stated in the advisory. If an attacker is able to reach the upload functionality, the flaw can be abused to achieve remote code execution.

Generated by OpenCVE AI on August 14, 2026 at 18:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Dell DSA‑2026‑329 security update to upgrade WMS to version 2605.0.2 or later
  • Configure the upload feature to accept only safe file types and enforce strict content‑type validation
  • Restrict the privileges of users who can access the upload functionality or enforce least‑privilege policies

Generated by OpenCVE AI on August 14, 2026 at 18:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Title Unrestricted Dangerous File Upload in Dell Wyse Management Suite Leading to Remote Code Execution

Fri, 14 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Description Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-14T16:43:51.874Z

Reserved: 2026-07-24T11:04:27.160Z

Link: CVE-2026-66271

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-14T16:16:59.030

Modified: 2026-08-14T17:20:13.880

Link: CVE-2026-66271

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T18:15:05Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type