Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability.
Dell ThinOS 10 has a flaw that lets an unauthenticated remote attacker run code within the application context. Successful exploitation could expose or alter information handled by the application.
- Severity
- CriticalCVSS 3.1 · 9.4
- Fix
- Not confirmedLast checked today
- Affected versions
- before 2605_10.2616
- Weakness
- CWE-284Improper Access Control
- Exploit likelihood
- 0.37% in 30 daysEPSS, higher than 30% of known flaws
- Affects
- ThinOS 10
- Exploited
- Not confirmedNo confirmation recorded
- CISA SSVC
- No known exploitationAutomatable: yes · Technical impact: total
- EU ID
- EUVD-2026-75573ENISA vulnerability database
How it works
- An attacker with remote access can reach ThinOS 10 without logging in.
- The flaw can be exploited without privileges or user interaction.
- Successful exploitation can let the attacker run arbitrary code within the application context.
What to do
Check the ThinOS version on each managed device and compare it with 2605_10.2616. Versions before 2605_10.2616 are affected.
Install ThinOS 10 version 2605_10.2616 or later using Dell's security advisory.
Technical details
CVE-2026-81046 is an access-control flaw in Dell ThinOS 10. Network access is required, but the attacker needs no login and no user interaction. CVSS 3.1 rates it critical with a 9.4 score.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required None Attacker needs no account or login
- User interaction None No victim action needed
- Scope Unchanged Impact stays within the same security authority
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact High Protected data can be changed with serious impact
- Availability impact Low Reduced performance or interruptions
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L Open in FIRST.org calculatorReferences
- cve.org · CVERecord vdb entry
- tenable.com · CVE-2026-81046 third party advisory vdb entry
- cvefeed.io · CVE-2026-81046 third party advisory vdb entry
- cveawg.mitre.org · CVE-2026-81046
- dell.com · dsa-2026-389-security-update-for-dell-thinos-10-for-multiple-vulnerabilities vendor-advisory NVD