CVE-2026-41120

PUBLISHED
Published: 25 Jun 2026, 13:28
Last modified:25 Jun 2026, 14:08

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.1 (cve.org)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

25 Jun 2026, 13:28
Published
Vulnerability first disclosed
25 Jun 2026, 14:08
Last Modified
Vulnerability information updated

Description

Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous Untrusted Data With Trusted Data vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.

CVSS Metrics

  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Techniques & Countermeasures

  • CWE-349Acceptance of Extraneous Untrusted Data With Trusted Data

    The product, when processing trusted data, accepts any untrusted data that is also included with the trusted data, treating the untrusted data as if it were trusted.

Affected Systems

  • dellwyse management suite

    < Version 5.5 HF1 or later

References (1)