CVE-2026-66271

7.2

Dell · Wyse Management Suite (WMS)

Dell Wyse Management Suite (WMS) versions prior to 2605.0.2 contain an unrestricted file upload vulnerability that may allow an authenticated attacker to execute arbitrary code.

Executive summary

An unrestricted file upload vulnerability in Dell Wyse Management Suite (WMS) versions prior to 2605.0.2 poses a significant risk for unauthorized system compromise.

Vulnerability

The application is susceptible to an unrestricted file upload flaw, identified as CWE-434, which allows a remote user with high privileges to upload malicious files. This vulnerability requires authenticated access to the management console to exploit.

Business impact

Successful exploitation of this vulnerability could lead to full system compromise, allowing an attacker to execute arbitrary code with the privileges of the WMS application. Given the CVSS score of 7.2, this represents a high-severity risk that could result in sensitive data exposure, loss of management control over connected Wyse endpoints, and significant operational disruption.

Remediation

Immediate Action: Update the Dell Wyse Management Suite to version 2605.0.2 or later immediately.

Proactive Monitoring: Review application access logs for unusual file upload activity or unauthorized access to administrative functions.

Compensating Controls: Ensure the WMS management interface is restricted to trusted administrative networks and protected by robust network access controls.

Exploitation status

Public Exploit Available: unknown

Analyst recommendation

The high severity of this flaw necessitates immediate attention. Administrators should prioritize upgrading the Wyse Management Suite to the latest version to prevent potential remote code execution by malicious insiders or compromised administrative accounts.

More Dell CVEs