Sceawere

Vulnerability Detail

CVE-2026-66272UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Dell Wyse Management Suite Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
2h ago
Vendor
Dell
Product
Wyse Management Suite (WMS)
Attack Type
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-08-14T16:16:59.143Z",
  "pubdate": "2026-08-14T16:16:59.143Z",
  "executiveSummary": "Dell Wyse Management Suite (WMS), specifically versions prior to 2605.0.2, contains a critical Missing Authentication for Critical Function vulnerability that exposes sensitive system data.\nThe vulnerability allows an unauthenticated remote attacker to bypass access controls and query sensitive endpoints, resulting in unauthorized information disclosure.\nThis flaw presents significant risk implications as leaked internal data can be leveraged by malicious actors to facilitate subsequent, more targeted compromise attempts against the infrastructure.\nExploitation requires network access to the vulnerable Dell Wyse Management Suite instance, but does not necessitate prior authentication or privileged credentials on the target system.\nOrganizations utilizing affected versions face heightened exposure due to the remote nature of the attack vector and the lack of pre-requisite authentication barriers for the impacted functionality.",
  "technicalDetails": "The vulnerability stems from a Missing Authentication for Critical Function flaw within Dell Wyse Management Suite (WMS) in versions prior to 2605.0.2.\nThe root cause lies in the application logic failing to properly validate user sessions and authentication tokens on specific API endpoints or critical functions responsible for handling administrative or system-level data.\nBecause access controls are absent or improperly enforced on these specific routines, an unauthenticated remote attacker can issue direct HTTP requests to the vulnerable endpoints.\nThe attack flow proceeds as follows: First, the adversary establishes network connectivity with the exposed Dell Wyse Management Suite interface. Second, the attacker formulates a targeted request directed at the inadequately protected component without supplying any session identifier or authentication header. Third, the application processes the request, bypasses access verification checks, and returns the requested sensitive data directly to the client in the HTTP response payload.\nThe affected component is exposed over the network, making it accessible to any remote entity capable of reaching the service instance.\nNo privileges are required to exploit this flaw, as the vulnerability explicitly permits unauthenticated interactions with functionality that should be restricted to authenticated administrative users.\nThe post-exploitation impact is characterized by unauthorized information disclosure, wherein internal configuration data, system identifiers, or other sensitive operational metrics are divulged to the attacker, potentially aiding in further reconnaissance and lateral movement."
}
CVE-2026-66272: Dell Wyse Management Suite Information Disclosure (MEDIUM Severity, CVSS: 5.3) - Sceawere