CVE-2026-22766

7.2

Dell · Wyse Management Suite

Dell Wyse Management Suite versions prior to 5.5 contain an unrestricted file upload vulnerability that allows a high privileged remote attacker to achieve remote code execution.

Executive summary

A critical file upload vulnerability in Dell Wyse Management Suite allows high privileged remote attackers to execute arbitrary code on the affected system.

Vulnerability

This flaw is classified as an Unrestricted Upload of File with Dangerous Type (CWE-434). It requires an attacker to possess high privileges and remote access to the management interface to successfully upload and execute malicious files.

Business impact

The ability for an attacker to achieve remote code execution on a management suite presents a significant risk to the entire managed infrastructure. Successful exploitation could lead to total system compromise, unauthorized data access, and the potential for lateral movement across the network. With a CVSS score of 7.2, this vulnerability is categorized as high severity and requires immediate attention to prevent unauthorized administrative control.

Remediation

Immediate Action: Update the Dell Wyse Management Suite to version 5.5 or later as specified in the vendor security advisory.

Proactive Monitoring: Review system access logs for any suspicious file upload activity or unauthorized changes to the management server configuration.

Compensating Controls: Restrict network access to the Wyse Management Suite administrative interface to trusted IP addresses only, and ensure that Web Application Firewalls are configured to block suspicious file extensions.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations using the Dell Wyse Management Suite must prioritize upgrading to version 5.5 immediately. Given the potential for total system compromise, failure to patch this vulnerability leaves the management infrastructure exposed to high privileged attackers. Administrators should verify their current version and apply the vendor-provided update as soon as possible.

More Dell CVEs

Sources