CVE-2026-23862

7.8

Dell · ThinOS

Dell ThinOS 10 contains a command injection vulnerability allowing local, low-privileged attackers to elevate privileges.

Executive summary

A command injection vulnerability in Dell ThinOS 10 could allow a low-privileged local attacker to achieve full system compromise via elevation of privileges.

Vulnerability

The vulnerability is a command injection flaw (CWE-77) occurring due to improper neutralization of special elements used in system commands. An attacker with low-level local access can trigger this flaw to execute arbitrary commands with higher privileges.

Business impact

The potential for privilege escalation poses a significant risk to the integrity and confidentiality of the affected thin client environment. Because an attacker can escalate to higher privileges, they may bypass security controls, access sensitive configuration data, or compromise the stability of the endpoint. With a CVSS score of 7.8, this vulnerability is considered High severity, reflecting its potential for total impact on the local system.

Remediation

Immediate Action: Update all affected Dell ThinOS 10 devices to version 2602_10.0573_T10 or later as specified in the vendor advisory.

Proactive Monitoring: Review system logs for unauthorized attempts to invoke shell commands or unusual execution patterns originating from low-privileged user accounts.

Compensating Controls: Restrict physical or local console access to thin client devices to prevent unauthorized users from reaching the command interface.

Exploitation status

Public Exploit Available: No confirmed public exploit available.

Analyst recommendation

Organizations utilizing Dell ThinOS should prioritize the deployment of the provided firmware update. Given the severity of command injection vulnerabilities, failure to patch may allow local actors to gain unauthorized control over the endpoint. Ensure that all devices are updated to the specified version to remediate the underlying flaw and restore system integrity.

More Dell CVEs

Sources