Description
Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
Published: 2026-09-15
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A file upload handler in Dell Wyse Management Suite does not validate the type of files that can be uploaded. An attacker who can reach the WMS application over the network can send a malicious file—such as a script or executable—to the server. The upload endpoint runs without authentication, and the uploaded content is executed with the privileges of the WMS service, allowing the attacker to run arbitrary commands and effectively take control of the underlying host.

Affected Systems

The vulnerability affects all Dell Wyse Management Suite installations with a version earlier than 2605.0.3.683. Systems running that release or newer are not impacted.

Risk and Exploitability

The CVSS base score of 8.6 reflects a high severity due to remote code execution without authentication. The EPSS score of less than 1% indicates that, while the vulnerability is technically exploitable, its current exploitation rate in the wild is very low. The vulnerability is not listed in CISA’s KEV catalog, and no widespread exploits have been reported, but the impact of a successful attack remains significant. The attack vector is inferred to be via a publicly accessible file‑upload endpoint on the WMS server.

Generated by OpenCVE AI on September 20, 2026 at 15:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Dell DSA‑2026‑387 to upgrade to version 2605.0.3.683 or later.
  • Disable or severely restrict the file‑upload functionality, allowing only non‑executable file types.
  • Place the WMS application behind a firewall or VPN and limit inbound traffic to trusted IP ranges.

Generated by OpenCVE AI on September 20, 2026 at 15:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:dell:wyse_management_suite:*:*:*:*:*:*:*:*

Sun, 20 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Title Unrestricted Dangerous File Upload in Dell Wyse Management Suite Allowing Remote Execution

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Title Unrestricted Dangerous File Upload in Dell Wyse Management Suite Allowing Remote Execution

Tue, 15 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell wyse Management Suite
Vendors & Products Dell
Dell wyse Management Suite

Tue, 15 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L'}


Subscriptions

Dell Wyse Management Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-16T15:51:26.604Z

Reserved: 2026-08-26T17:05:27.563Z

Link: CVE-2026-81236

cve-icon Vulnrichment

Updated: 2026-09-16T15:42:32.520Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T18:19:24.147

Modified: 2026-09-21T17:31:44.393

Link: CVE-2026-81236

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:15:17Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type