Description
Dell ThinOS 10, versions prior to 2605_10.2616, contain a Missing Support for Integrity Check vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution.
Published: 2026-09-10
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local Arbitrary Code Execution
Action: Immediate Patch
AI Analysis

Impact

Dell ThinOS 10 firmware versions before 2605_10.2616 lack a critical integrity check, a weakness classified as CWE-353, which allows a high privileged attacker with local access to execute arbitrary code. This vulnerability requires local administrative rights and directly compromises the confidentiality and integrity of the device.

Affected Systems

Dell ThinOS 10 firmware versions prior to 2605_10.2616 are affected; newer firmware releases contain the fix and are not vulnerable.

Risk and Exploitability

The CVSS score of 4.4 indicates moderate overall severity, but the local arbitrary code execution capability makes the risk high in environments where local privileged access is possible. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, implying no known public exploits at this time. The likely attack vector is local privileged access, as local access.

Generated by OpenCVE AI on September 10, 2026 at 17:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell ThinOS 10 security update that addresses the missing integrity check, available from Dell Support.
  • Limit local privileged access to trusted administrators only to reduce exploitation likelihood.
  • Enforce strict role-based access control and audit local privileged accounts.

Generated by OpenCVE AI on September 10, 2026 at 17:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation to Execute Arbitrary Code in Dell ThinOS 10

Thu, 10 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description Dell ThinOS 10, versions prior to 2605_10.2616, contain a Missing Support for Integrity Check vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution.
Weaknesses CWE-353
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-11T03:56:45.217Z

Reserved: 2026-08-26T15:50:35.363Z

Link: CVE-2026-81049

cve-icon Vulnrichment

Updated: 2026-09-10T16:02:04.211Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-10T16:17:57.670

Modified: 2026-09-11T04:17:57.467

Link: CVE-2026-81049

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T17:45:16Z

Weaknesses
  • CWE-353

    Missing Support for Integrity Check