Description
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.
Published: 2026-08-14
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell Wyse Management Suite versions prior to 2605.0.2 contain an unrestricted file upload flaw that allows a high‑privileged remote attacker to upload files of dangerous types. The vulnerability falls under CWE‑434 and can lead to direct remote code execution on the affected system if the attacker succeeds in uploading a malicious payload. The impact is broad, potentially affecting system confidentiality, integrity, and availability as the attacker gains the ability to run arbitrary code on the server.

Affected Systems

The affected product is Dell Wyse Management Suite (WMS) for all versions earlier than 2605.0.2.

Risk and Exploitability

The CVSS score is 7.2, indicating a high severity. No EPSS score is published, so the likelihood of exploitation is currently unknown. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote, requiring high‑privileged access, as stated in the advisory. If an attacker is able to reach the upload functionality, the flaw can be abused to achieve remote code execution.

Generated by OpenCVE AI on August 14, 2026 at 18:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Dell DSA‑2026‑329 security update to upgrade WMS to version 2605.0.2 or later
  • Configure the upload feature to accept only safe file types and enforce strict content‑type validation
  • Restrict the privileges of users who can access the upload functionality or enforce least‑privilege policies

Generated by OpenCVE AI on August 14, 2026 at 18:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:dell:wyse_management_suite:*:*:*:*:*:*:*:*

Mon, 17 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell wyse Management Suite
Vendors & Products Dell
Dell wyse Management Suite

Sat, 15 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 14 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Title Unrestricted Dangerous File Upload in Dell Wyse Management Suite Leading to Remote Code Execution

Fri, 14 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Description Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Wyse Management Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-15T03:55:48.656Z

Reserved: 2026-07-24T11:04:27.160Z

Link: CVE-2026-66271

cve-icon Vulnrichment

Updated: 2026-08-14T16:43:48.167Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-14T16:16:59.030

Modified: 2026-08-18T11:08:42.470

Link: CVE-2026-66271

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T11:01:07Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type