Dell ThinOS 10 OS Command Injection and Access Control Vulnerabilities

Release Date: 10th September 2026

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that operate Dell Wyse thin client devices running Dell ThinOS 10. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-81467, CVE-2026-81046, and CVE-2026-81468 are three critical vulnerabilities in Dell ThinOS 10, the purpose-built operating system running on Dell Wyse thin client devices, widely deployed by organizations and government agencies for virtual desktop infrastructure (VDI) and centrally-managed endpoint environments.

CVE-2026-81467 is an OS command injection flaw exploitable by an unauthenticated remote attacker.

CVE-2026-81046 is a protection mechanism failure (improper access control) also exploitable without authentication, allowing arbitrary code execution within the application context; and CVE-2026-81468 is a related OS command injection flaw requiring a high-privileged remote attacker. All three affect the same ThinOS 10 versions and share the same fixed release, so they are combined into this single advisory.

Reference

  1. https://www.cve.org/CVERecord?id=CVE-2026-81467
  2. https://www.cve.org/CVERecord?id=CVE-2026-81046
  3. https://www.cve.org/CVERecord?id=CVE-2026-81468
  4. https://www.dell.com/support/kbdoc/en-us/000502746/dsa-2026-389-security-update-for-dell-thinos-10-for-multiple-vulnerabilities