CVE-2026-66270
7.2Dell · Wyse Management Suite (WMS)
Dell Wyse Management Suite (WMS) versions prior to 2605.0.2 contain an unrestricted file upload vulnerability that may allow an authenticated attacker to execute arbitrary code.
Executive summary
An unrestricted file upload vulnerability in Dell Wyse Management Suite (WMS) versions prior to 2605.0.2 poses a significant risk for unauthorized system compromise.
Vulnerability
The application is susceptible to an unrestricted file upload flaw, identified as CWE-434, which allows a remote user with high privileges to upload malicious files. This vulnerability requires authenticated access to the management console to exploit.
Business impact
Exploitation of this vulnerability allows an authenticated attacker to bypass file type restrictions, potentially leading to remote code execution. With a CVSS score of 7.2, this vulnerability could result in unauthorized administrative access, data theft, and the compromise of all managed endpoints within the WMS environment.
Remediation
Immediate Action: Update the Dell Wyse Management Suite to version 2605.0.2 or later immediately.
Proactive Monitoring: Monitor server logs for suspicious file uploads or unexpected modifications to the application directory.
Compensating Controls: Restrict administrative access to the WMS console to specific, authorized IP addresses and implement strict file integrity monitoring.
Exploitation status
Public Exploit Available: unknown
Analyst recommendation
Organizations should treat this as a high-priority update. Promptly upgrading the WMS platform to the patched version is essential to secure the management infrastructure against potential exploitation.