Description
Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
Published: 2026-09-15
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an unrestricted upload of files with dangerous types in Dell Wyse Management Suite, exposing the system to remote code execution. An unauthenticated attacker who can access the management interface can upload a malicious file that the server processes or executes, potentially giving the attacker full control of the host. This flaw is a classic file‑upload weakness that bypasses type validation and is the root cause behind the remote execution risk.

Affected Systems

Dell Wyse Management Suite versions prior to 2605.0.3.683 are affected. The flaw operates in any deployment of the product, independent of the underlying operating system, and impacts all instances that have not applied the 2605.0.3.683 update or later.

Risk and Exploitability

The likelihood of exploitation is reported to be very low, with an EPSS score of <1%, but the CVSS score of 8.6 classifies it as high severity and indicates a potentially severe impact if any attacker succeeds. The attack surface is broad because the vulnerability is reachable through any unauthenticated remote connection to the management interface. The vulnerability does not require privileged access or local code, and the lack of authentication into the upload feature creates a very accessible vector. No public exploit has been disclosed in the advisory; this statement is inferred based on the lack of mention in the documentation and the low exploitation probability reflected in the EPSS.

Generated by OpenCVE AI on September 20, 2026 at 15:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Dell Wyse Management Suite update to version 2605.0.3.683 or later, as detailed in Dell’s security advisory.
  • Restrict network access to the WMS server by implementing IP filtering or VPN access so only trusted administrators can reach the management interface.
  • Configure the application to accept only pre-approved file types and enforce strict MIME type validation to prevent the processing of suspicious uploads.

Generated by OpenCVE AI on September 20, 2026 at 15:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:dell:wyse_management_suite:*:*:*:*:*:*:*:*

Sun, 20 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Title Unrestricted File Upload Leading to Remote Code Execution in Dell Wyse Management Suite

Thu, 17 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Title Unrestricted File Upload Leading to Remote Code Execution in Dell Wyse Management Suite

Wed, 16 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unrestricted File Upload Leading to Remote Code Execution in Dell Wyse Management Suite

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell wyse Management Suite
Vendors & Products Dell
Dell wyse Management Suite

Tue, 15 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L'}


Subscriptions

Dell Wyse Management Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-17T11:58:09.376Z

Reserved: 2026-08-26T17:05:27.564Z

Link: CVE-2026-81239

cve-icon Vulnrichment

Updated: 2026-09-15T19:07:17.455Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T18:19:24.513

Modified: 2026-09-21T17:31:21.500

Link: CVE-2026-81239

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:15:17Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type