PT-2026-52389 · Dell · Wyse Management Suite

CVE-2026-41120

·

Published

2026-06-25

·

Updated

2026-07-19

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell Wyse Management Suite versions prior to 5.5 HF1
Description An issue exists where the system accepts extraneous untrusted data mixed with trusted data. This occurs due to improper input validation, allowing attacker-controlled data to be processed as trusted server-side information. A low privileged attacker with remote access can exploit this by sending crafted requests to smuggle untrusted data into a trusted execution path, resulting in remote code execution on the server. This could lead to a full compromise of the management plane and control over managed endpoints.
Recommendations Upgrade to WMS 5.5 HF1.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41120

Affected Products

Wyse Management Suite