Critical Vulnerabilities in Dell Wyse Management Suite Enable Remote Code Execution

Critical Vulnerabilities in Dell Wyse Management Suite Enable Remote Code Execution

First seen 29 Jun 2026, 19:04 UTC GbhackersCybersecuritynewsCcb.Belgium.Benvd.nist.govwww.dell.com 91% similarity 72.9
Share:

Article Content

Browse articles
ThreatCluster

Dell Technologies has disclosed critical vulnerabilities in its Wyse Management Suite (WMS) that allow remote attackers to execute arbitrary code. The vulnerabilities, identified as CVE-2026-41120 and CVE-2026-49506, affect WMS versions prior to 5.5 HF1. CVE-2026-41120, with a CVSS score of 9.8, enables low-privileged attackers to exploit the flaw without user interaction. CVE-2026-49506 is a path traversal vulnerability requiring high privileges for exploitation. Organizations using WMS are at risk of significant impacts on confidentiality, integrity, and availability. Dell has released a patch for these vulnerabilities, urging immediate upgrades. Security teams are advised to enhance monitoring and review access controls to mitigate risks. The vulnerabilities were disclosed by security researcher Tien Phan.

Key Points: • CVE-2026-41120 allows low-privileged attackers to execute remote code with a CVSS score of 9.8. • CVE-2026-49506 is a path traversal vulnerability requiring high privileges for exploitation. • Dell has released a patch for WMS, urging immediate upgrades to mitigate risks.

ThreatCluster AI

Timeline

2026-03-20
CVE-2026-33017 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-08
Patch released for WMS
Dell released version 5.5 HF1 to address the critical vulnerabilities in WMS.
Gbhackers
2026-06-25
CVE-2026-41120 published
A critical vulnerability allowing low-privileged remote code execution was disclosed.
Gbhackers
2026-06-25
CVE-2026-49506 published
A path traversal vulnerability was disclosed, enabling high-privileged remote code execution.
Gbhackers

Community

Browse all →