CVE-2026-22765

8.8

Dell · Wyse Management Suite

A missing authorization vulnerability in Dell Wyse Management Suite prior to version 5.5 allows low privileged remote attackers to gain elevated privileges.

Executive summary

A missing authorization vulnerability in Dell Wyse Management Suite allows authenticated attackers to perform unauthorized privilege escalation, posing a high risk to administrative security.

Vulnerability

This vulnerability is classified as a Missing Authorization flaw (CWE-862). It permits an attacker who has already obtained low level remote access to bypass authorization checks and achieve an elevation of privilege within the management environment.

Business impact

The ability for a low privileged user to escalate privileges represents a significant threat to the integrity and confidentiality of the management infrastructure. Given the CVSS score of 8.8, this flaw could allow an attacker to gain full administrative control over the suite, potentially resulting in unauthorized configuration changes, data exfiltration, or total system compromise.

Remediation

Immediate Action: Organizations must update the Dell Wyse Management Suite to version 5.5 or later to resolve the underlying authorization failure.

Proactive Monitoring: Security teams should review system access logs for unusual administrative activity or unauthorized command execution originating from low privilege accounts.

Compensating Controls: While a patch is available, deploying a Web Application Firewall (WAF) can help monitor for and block suspicious traffic patterns directed at the management interface.

Exploitation status

Public Exploit Available: False

Analyst recommendation

The severity of this vulnerability, combined with the potential for total system compromise, mandates immediate remediation. Administrators should prioritize the deployment of the version 5.5 update across all affected Wyse Management Suite instances to neutralize the privilege escalation risk. Failure to apply this update leaves the management infrastructure vulnerable to internal actors or compromised accounts seeking to expand their access.

More Dell CVEs

Sources