{"id":"CVE-2026-81240","title":"Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability","summary":"Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to…","severity":"high","cvss":8.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L","cwe":["CWE-434"],"vendor":"dell","product":"wyse_management_suite","affected":["wyse_management_suite < 2605.0.3.683"],"patched":["wyse_management_suite 2605.0.3.683"],"published":"2026-09-15","updated":"2026-09-21","sourceUpdated":"2026-09-21T17:31:15.503","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-81240","references":[{"url":"https://www.dell.com/support/kbdoc/en-us/000502744/dsa-2026-387-security-update-for-dell-wyse-management-suite-wms-for-multiple-vulnerabilities","label":"security_alert@emc.com"}],"tags":["nvd","cve.org"],"epss":0.00361,"epssPercentile":0.29766,"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"total","timestamp":"2026-09-16T03:56:56.406428Z"},"ingestedAt":"2026-09-15T18:41:59.146Z","slug":"CVE-2026-81240","body":"## Overview\n\nDell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.\n\n## Affected\n\n- `wyse_management_suite < 2605.0.3.683`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `wyse_management_suite 2605.0.3.683`","depth":"twilight","depthScore":47,"depthScoreParts":{"impact":47.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}