Description
Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
Published: 2026-09-24
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access
Action: Immediate patch
AI Analysis

Impact

Dell ThinOS 10 is vulnerable to a missing authentication flaw for a critical function, which can allow an attacker without credentials to manipulate system operations remotely. The weakness is classified as CWE‑306, indicating that authentication checks are insufficient. This flaw can compromise confidentiality and integrity of data controlled by the ThinOS instance, potentially allowing the attacker to execute privileged commands or modify configuration settings. The description confirms that unauthorized access is possible but does not specify whether arbitrary code execution is feasible.

Affected Systems

All Dell ThinOS 10 releases published before SecurityAddon_2605.10.2766_T10 are affected. In particular, any system running a version of ThinOS 10 that has not incorporated the security addon update SecurityAddon_2605.10.2766_T10 or later is vulnerable.

Risk and Exploitability

The CVSS score of 8.6 indicates a high‑severity risk, and the EPSS score is not available, meaning current exploit data is insufficient to estimate spike probability. The vulnerability is not listed in the CISA KEV catalog, which suggests that it has not yet been observed in the wild, but it remains a critical patchable issue. The likely attack vector is remote access over the network, inferred from the description that an unauthenticated attacker can exploit the flaw. An attacker would need the ThinOS system to be reachable and would benefit from any additional local privileges once the critical function is accessed.

Generated by OpenCVE AI on September 25, 2026 at 05:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Dell ThinOS 10 security update that includes SecurityAddon_2605.10.2766_T10 or a newer update
  • Upgrade to the latest version of Dell ThinOS 10 after applying the security addon update
  • Configure network segmentation and firewall rules to restrict remote access to ThinOS management interfaces
  • Validate and enforce authentication mechanisms on all critical ThinOS functions to ensure proper access control

Generated by OpenCVE AI on September 25, 2026 at 05:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell thinos
Vendors & Products Dell
Dell thinos

Fri, 25 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Title Missing Authentication in Dell ThinOS 10 Enabling Unauthenticated Remote Access

Thu, 24 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 24 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-24T18:54:50.476Z

Reserved: 2026-08-26T20:04:54.731Z

Link: CVE-2026-81455

cve-icon Vulnrichment

Updated: 2026-09-24T18:54:33.905Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-24T19:17:17.463

Modified: 2026-09-24T19:37:47.987

Link: CVE-2026-81455

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T14:16:02Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function