Dell Wyse Management Suite Critical RCE Chain (CVE-2026-41120, CVE-2026-49506) — Threadlinqs Intelligence
As of 2026-07-11, Dell Wyse Management Suite Critical RCE Chain (CVE-2026-41120, CVE-2026-49506) is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 16 indicators of compromise.
Threat ID: TL-2026-1204 · Severity: CRITICAL · CVSS: 9.8 · Status: ACTIVE · Category: VULNERABILITY
Dell Wyse Management Suite (WMS) versions prior to 5.5 HF1 are vulnerable to two chainable flaws: CVE-2026-41120 (CVSS 9.8), an unauthenticated, no-user-interaction remote code execution stemming from
Dell Wyse Management Suite is the centralized, on-premises endpoint management platform used to provision, monitor, and remotely administer fleets of Dell Wyse thin clients across enterprise environments. Because WMS holds administrative control over thousands of managed endpoints, compromise of a single WMS instance can cascade into mass endpoint compromise and lateral movement across an organization's thin-client fleet.
CVE-2026-41120 is the more severe of the two flaws (CVSS 3.1: 9.8, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). It is classified as CWE-349 (Acceptance of Extraneous Untrusted Data With Trusted Data): the WMS server, when processing a request that legitimately contains trusted data, also accepts additional attacker-supplied data bundled alongside it and processes that untrusted payload as if it were trusted. This class of flaw is typically exploited by appending or interleaving malicious parameters, headers, or serialized fields into an otherwise-legitimate trusted request, causing the server-side handler to execute or act upon the injected content. The vulnerability requires no authentication, no privileges, and no user interaction, and is remotely reachable over the network — most WMS deployments expose the management web interface on TCP 443/8443. Because trust boundary enforcement fails at the point of data acceptance rather than during a later authorization check, an unauthenticated attacker can reach code paths intended only for the trusted internal data flow, resulting in full remote code execution with complete loss of confidentiality, integrity, and availability on the underlying WMS server (and by extension, over managed thin-client fleets).
CVE-2026-49506 (CVSS 3.1: 7.2, AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) is a path-traversal vulnerability (CWE-22, Improper Limitation of a Pathname to a Restricted Directory) that requires high privileges to trigger. An authenticated, highly-privileged attacker can manipulate file-path input (e.g., via directory-traversal sequences such as ../ in upload, config, or file-management endpoints) to escape the intended restricted directory, read or write files outside the sanctioned path, and potentially achieve remote code execution by planting or overwriting server-side executable content. Dell's advisory notes this class of flaw is often chained with credential-theft or privilege-escalation techniques in real-world attacks, which lowers the practical barrier to exploitation despite the nominal high-privilege requirement — an attacker who first obtains low-privileged access (for example via CVE-2026-41120) could pivot into CVE-2026-49506 to entrench file-system-level persistence.
Both flaws were responsibly disclosed by security researcher Tien Phan and are documented in Dell Security Advisory DSA-2026-225 (initial release 2026-06-16). Dell remediated both issues in Wyse Management Suite 5.5 HF1, released 2026-05-08. As of this research, no public proof-of-concept exploit code, in-the-wild exploitation, or CISA KEV catalog listing has been identified for either CVE; risk assessment is therefore based on the vulnerability characteristics (unauthenticated, network-reachable, no user interaction) rather than confirmed active exploitation. Given the centralized administrative role WMS plays in Dell thin-client environments, unpatched internet-exposed or improperly segmented instances represent a high-value target for both opportunistic and targeted actors seeking to establish a foothold and pivot into managed endpoint fleets.
Weaknesses (CWE)
CWE-349, CWE-22
Target sectors: enterprise it, government administration, health, finance, education, retail, manufacturing
Target regions: Global
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 16 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-41120, CVE-2026-49506, T1190, T1203, T1059, T1505, T1505.003, T1068, T1211, T1070, T1552, T1083