PT-2026-52389 · Dell · Wyse Management Suite
CVE-2026-41120
·
Published
2026-06-25
·
Updated
2026-07-19
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dell Wyse Management Suite versions prior to 5.5 HF1
Description
An issue exists where the system accepts extraneous untrusted data mixed with trusted data. This occurs due to improper input validation, allowing attacker-controlled data to be processed as trusted server-side information. A low privileged attacker with remote access can exploit this by sending crafted requests to smuggle untrusted data into a trusted execution path, resulting in remote code execution on the server. This could lead to a full compromise of the management plane and control over managed endpoints.
Recommendations
Upgrade to WMS 5.5 HF1.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wyse Management Suite