CVE-2026-22765Disclosure(dell / wyse_management_suite)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch dell wyse_management_suite systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Dell Wyse Management Suite, versions prior to WMS 5.5, contain a Missing Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of Privileges.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wyse_management_suite

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 11 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 9 signals
  • Disclosure: 7 classified signals
  • Peaked 6d ago at 3 mentions (2026-02-24); latest day: 1
  • 11 total mentions across 7 days

Affected systems

Vendors
Products
wyse_management_suite

Deep dive

Activity timeline11 mentions / 7d
01223Mentions · 2026-02-24: 3Mentions · 2026-02-25: 3Mentions · 2026-03-24: 1Mentions · 2026-03-25: 1Mentions · 2026-03-26: 1Mentions · 2026-03-31: 1Mentions · 2026-04-08: 1PoC Mentioned / Linked · 2026-03-24: 1PoC Mentioned / Linked · 2026-03-26: 1Patch / Workaround · 2026-02-24: 1Patch / Workaround · 2026-03-25: 1Technical Details · 2026-02-24: 3Technical Details · 2026-02-25: 2Technical Details · 2026-03-24: 1Technical Details · 2026-03-25: 1Technical Details · 2026-03-26: 1Technical Details · 2026-03-31: 102-2402-2503-2403-2503-2603-3104-08
Signal classification4 categories
Disclosure
763.6%
Patch
218.2%
PoC
19.1%
General
19.1%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-02-243
Disclosure2Patch1
2026-02-253
Disclosure3
2026-03-241
PoC1
2026-03-251
Patch1
2026-03-261
Disclosure1
2026-03-311
Disclosure1
2026-04-081
General1
Full discourse11 posts
  • Gray Hats@the_yellow_fall
    Disclosure

    A critical RCE chain has been found in Dell Wyse Management Suite (WMS) on-prem. Learn how CVE-2026-22765 and CVE-2026-22766 bypass security in version 5.5. #DellWyse #RCE #CyberSecurity #PT_SWARM #VulnerabilityAlert #Infosec #ThinClient https://meterpreter.org/the-thin-client-trap-how-a-vulnerability-chain-in-dell-wyse-management-suite-unlocks-remote-code-execution/ https://t.co/E1aKnSE9y8

    Post summary

    A critical RCE chain (CVE-2026-22765/22766) has been discovered in Dell Wyse Management Suite v5.5, with a PoC referenced via a linked article, but no exploitation or patch information is reported.

    04072608
    10.9K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Dell Wyse Management Suite の 2 件の脆弱性を連鎖:システム全体の侵害につながる恐れ https://iototsecnews.jp/2026/03/24/dell-wyse-management-flaws-could-lead-to-full-system-compromise/ この攻撃の原因は、デバイス登録時の認証不備や API の制限不足といった、複数の小さなロジック欠陥の連鎖にあります。具体的には、脆弱性 CVE-2026-22765 を悪用する攻撃者に対して不適切にトークンが付与され、その後のプロセスで API の直接呼び出しを許すという状況に陥ります。さらに 脆弱性 CVE-2026-22766 の悪用により、特定のプロパティ操作と認証の回避が引き起こされ、RCE につながってしまいます。些細に見える小さな問題であっても、それらが連鎖することで、システム全体の完全侵害を許す深刻な脅威となります。ご利用のチームは、ご注意ください。 #CVE202622765 #CVE202622766 #Dell #Vulnerability #WyseManagementSuite

    Post summary

    The article announces two chained CVEs (CVE-2026-22765 and CVE-2026-22766) in Dell Wyse Management Suite, explaining how flawed token issuance and API misuse can lead to remote code execution, with no proof of exploit, patch discussion or real‑world use noted.

    01000198
    481 followersView on X
  • Autumn Good@autumn_good_35
    PoC

    🚨🚨🚨 『The final step was chaining all discovered vulnerabilities into an exploit chain, which allowed me to achieve unauthenticated remote code execution (RCE)』 CVE-2026-22765 CVE-2026-22766 unauthenticated RCE in Dell Wyse Management Suite https://swarm.ptsecurity.com/business-logic-and-chains-unauthenticated-rce-in-dell-wyse-management-suite/

    Post summary

    A researcher chained multiple discovered CVEs to achieve unauthenticated remote code execution in Dell Wyse Management Suite, documenting the PoC in an online article.

    00001411
    6.7K followersView on X
  • Threat Intelligence@threatintel
    General

    #ThreatProtection #CVE-2026-22765 - Dell Wyse Management Suite #vulnerability, read more about Symantec's protection: https://www.broadcom.com/support/security-center/protection-bulletin/cve-2026-22765-dell-wyse-management-suite-vulnerability

    Post summary

    The post merely cites CVE‑2026‑22765 for Dell Wyse Management Suite and links to a protection bulletin, offering no further detail on exploitation or mitigation.

    00000865
    115.0K followersView on X
  • CybrPulse@CybrPulse
    Patch

    Two Dell Wyse Management Suite flaws chain to unauthenticated RCE. CVE-2026-22765 (CVSS 8.8) gets rogue device to admin; CVE-2026-22766 (CVSS 7.2) uploads a webshell. Patched in WMS 5.5. If you manage Dell thin clients, check your version. https://cybersecuritynews.com/dell-wyse-management-vulnerabilities/ #infosec

    Post summary

    Two Dell Wyse Management Suite vulnerabilities enabling unauthenticated remote code execution have been disclosed, but a patch is already available in version 5.5.

    0000056
    22 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    We have just added an important vulnerability affecting Dell Wyse Management Suite (CVE-2026-22765) https://vuldb.com/?id.347655

    Post summary

    A new vulnerability (CVE-2026-22765) affecting Dell Wyse Management Suite has been added to a vulnerability database.

    0000065
    2.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22765 Dell Wyse Management Suite, versions prior to WMS 5.5, contain a Missing Authorization vulnerability. A low privileged attacker with remote access could potentially e… https://www.cve.org/CVERecord?id=CVE-2026-22765

    Post summary

    The text announces a missing authorization flaw in Dell Wyse Management Suite, indicating that low‑privileged remote attackers could potentially exploit it.

    00000115
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-22765 Dell Wyse Management Suite Remote Privilege Escalation in Versions Below 5.5 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-22765

    Post summary

    Dell Wyse Management Suite versions below 5.5 are vulnerable to remote privilege escalation (CVE-2026-22765). No PoC, exploit, or patch details are provided.

    0000044
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-22765: HIGH] Dell Wyse Management Suite <WMS 5.5 has a Missing Authorization flaw allowing remote attackers to conduct Elevation of Privileges. Upgrade to the secure version now.#cve,CVE-2026-22765,#cybersecurity https://cvefind.com/CVE-2026-22765

    Post summary

    Dell Wyse Management Suite <WMS 5.5 has a missing authorization flaw (CVE-2026-22765) that permits remote privilege escalation; users are urged to upgrade to the secure version.

    0000060
    584 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-22765** pertains to a **Missing Authorization vulnerability** in **Dell Wyse Management Suite (WMS)** versions prior to **5.5**. This flaw allows a **low-privileged attacker** with **remote access** to exploit the system, potentially leading to **Elevation of Privileges (EoP)**. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #AuthBypass #DDoS https://cvetodo.com/cve/CVE-2026-22765

    Post summary

    The post announces CVE‑2026‑22765 as a missing‑authorization flaw in Dell Wyse Management Suite that allows low‑privileged remote attackers to elevate privileges, with no PoC, exploit, patch, or active exploitation reported.

    0000045
    20 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-22765 - High Dell Wyse Management Suite, versions prior to WMS 5.5, contain a Missing Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability... https://www.thehackerwire.com/vulnerability/CVE-2026-22765/ https://t.co/eJQb2L5gTS

    Post summary

    Dell Wyse Management Suite versions before 5.5 contain a missing authorization flaw that could allow low‑privileged remote attackers to exploit the system, as reported by The Hacker Wire.

    0000051
    113 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdellwyse_management_suite---

Explore more