---
id: CVE-2026-81467
title: 'Dell ThinOS 10, versions prior to 2605_10'
summary: >-
  Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper
  Neutralization of Special Elements used in an OS Command ('OS Command
  Injection') vulnerability. An unauthenticated attacker with remote access
  could potentially explo…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: dell
product: thinos
affected:
  - thinos < 2605_10.2616
patched:
  - thinos 2605_10.2616
published: '2026-09-10'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T20:47:19.350'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81467'
references:
  - url: >-
      https://www.dell.com/support/kbdoc/en-us/000502746/dsa-2026-389-security-update-for-dell-thinos-10-for-multiple-vulnerabilities
    label: security_alert@emc.com
tags:
  - nvd
  - cve.org
epss: 0.02987
epssPercentile: 0.86765
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-11T03:56:48.180429Z'
ingestedAt: '2026-09-13T23:56:43.863Z'
---

## Overview

Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution.

## Affected

- `thinos < 2605_10.2616`

## Remediation

Upgrade past the affected range:

- `thinos 2605_10.2616`
