Description
Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Arbitrary Code Execution within the application context.
Published: 2026-09-10
Score: 9.4 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Dell ThinOS 10 contains a Protection Mechanism Failure (CWE-284) that enables an unauthenticated attacker with remote access to potentially attain arbitrary code execution inside the ThinOS application context. The flaw bypasses normal protective controls, allowing malicious code to run with the privileges of the ThinOS process, threatening confidentiality and integrity of the system.

Affected Systems

All Dell ThinOS 10 releases older than 2605_10.2616 are affected. No other vendors or product lines are listed in the current advisory.

Risk and Exploitability

The CVSS score of 9.4 denotes a critical severity and indicates that environment. Because the EPSS score is not available and the vulnerability exact likelihood of exploitation is uncertain, yet the combination of remote unauthenticated access and high exploit if the ThinOS management interfaces are reachable. It is inferred that the ThinOS management interfaces are a likely attack surface, though this is not explicitly confirmed in the advisory.

Generated by OpenCVE AI on September 10, 2026 at 18:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell ThinOS 10 update 2605_10.2616 or later to all affected devices, following the guidance in the Dell security advisory.
  • If immediate patching is not possible, block external network access to ThinOS management interfaces using firewalls or network segmentation to deny unauthenticated remote connections.
  • Enforce strict authentication and role‑based access controls on ThinOS interfaces, ensuring only authorized personnel can reach management functions.

Generated by OpenCVE AI on September 10, 2026 at 18:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Title Protection Mechanism Failure in Dell ThinOS 10 Enables Remote Unauthorized Code Execution

Thu, 10 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Title Protection Mechanism Failure in Dell ThinOS 10 Enables Remote Unauthorized Code Execution

Thu, 10 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Arbitrary Code Execution within the application context.
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 9.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-10T16:21:46.997Z

Reserved: 2026-08-26T15:50:35.362Z

Link: CVE-2026-81046

cve-icon Vulnrichment

Updated: 2026-09-10T16:21:42.576Z

cve-icon NVD

Status : Received

Published: 2026-09-10T16:17:57.417

Modified: 2026-09-10T17:17:06.220

Link: CVE-2026-81046

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T18:15:06Z

Weaknesses