CVE-2026-82157

8.3

Dell · ThinOS 10

Dell ThinOS 10 contains an improper certificate validation vulnerability that allows unauthenticated adjacent attackers to bypass protection mechanisms and gain unauthorized access.

Executive summary

An improper certificate validation flaw in Dell ThinOS 10 allows unauthenticated attackers on the adjacent network to bypass security controls and gain unauthorized access to the system.

Vulnerability

The vulnerability is an improper certificate validation flaw (CWE-295) that allows an unauthenticated attacker with adjacent network access to intercept or spoof communications, leading to unauthorized access and security bypass.

Business impact

The high CVSS score of 8.3 reflects the significant risk posed by this vulnerability, as it allows attackers to compromise the integrity and confidentiality of communication channels used by ThinOS devices. Unauthorized access could lead to the exposure of sensitive session data, configuration information, or the takeover of thin client sessions, resulting in potential data theft or broader organizational network compromise.

Remediation

Immediate Action: Update Dell ThinOS 10 to the SecurityAddon_2605.10.2766_T10 version or later as specified in the official vendor advisory.

Proactive Monitoring: Monitor network traffic for anomalous certificate handshake failures or unauthorized connection attempts originating from the adjacent network segment.

Compensating Controls: Implement strict network segmentation and port security on switches to prevent unauthorized devices from gaining adjacent network access to ThinOS endpoints.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for unauthorized access and the high severity of this vulnerability, administrators should prioritize the deployment of the SecurityAddon_2605.10.2766_T10 update across all affected Dell ThinOS 10 environments. Ensuring that endpoints are patched immediately will mitigate the risk of attackers exploiting certificate validation gaps to compromise thin client security.

More Dell CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources

Originally found and disclosed by Dell would like to thank saltedfish for reporting this issue., per the CVE Program record.