Sceawere

Vulnerability Detail

CVE-2026-66271UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Dell Wyse Management Suite RCE Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
2h ago
Vendor
Dell
Product
Wyse Management Suite (WMS)
Attack Type
CWE-434: Unrestricted Upload of File with Dangerous Type
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-08-14T16:16:59.030Z",
  "pubdate": "2026-08-14T16:16:59.030Z",
  "executiveSummary": "Dell Wyse Management Suite (WMS) versions prior to 2605.0.2 suffer from an Unrestricted Upload of File with Dangerous Type vulnerability. This security defect introduces severe risk implications to enterprise environments utilizing the centralized management platform.\nThe vulnerability allows a high-privileged attacker with remote access capabilities to execute arbitrary code on the underlying operating system. Successful exploitation leads directly to Remote Code Execution (RCE), compromising the confidentiality, integrity, and availability of the affected system and potentially the managed thin client endpoints.\nThe primary prerequisite for exploitation is the possession of high privileges within the application, combined with remote network access to the target deployment. Mitigation requires administrative action to address the insecure file upload mechanism.",
  "technicalDetails": "The vulnerability resides within the file upload mechanisms of Dell Wyse Management Suite (WMS) in versions prior to 2605.0.2. The root cause is the inadequate validation and sanitization of user-supplied files, specifically the failure to restrict file extensions, MIME types, and internal content structures before storing them on the filesystem.\nThe vulnerable component handles administrative file submissions, such as firmware updates, configuration packages, or supplementary assets. Because the application fails to enforce strict type checking and extension blocklisting, an authenticated user possessing high privileges can supply malicious payloads disguised as or embedded within legitimate update formats.\nThe attack flow proceeds as follows: First, the attacker establishes remote access to the administrative interface of the Dell Wyse Management Suite. Second, leveraging high-privileged credentials, the attacker navigates to the susceptible file upload functionality. Third, the attacker crafts and uploads a payload containing dangerous file types, such as executable scripts or binary code designed to interact with the application runtime environment.\nDue to insufficient input validation, the application writes the malicious file to a web-accessible directory or executes it directly within the context of the service account. The network exposure is remote, leveraging the standard HTTP or HTTPS management ports exposed by the application server.\nThe post-exploitation impact includes complete system compromise. Because the application often runs with elevated system or administrative privileges, executing arbitrary code allows the threat actor to establish persistent access, pivot within the internal network, exfiltrate sensitive data, or manipulate connected Dell Wyse thin client endpoints managed by the suite."
}
CVE-2026-66271: Dell Wyse Management Suite RCE Vulnerability (HIGH Severity, CVSS: 7.2) - Sceawere