CVE-2026-22766Disclosure(dell / wyse_management_suite)

LOWCVSS 7.2 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch dell wyse_management_suite systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Dell Wyse Management Suite, versions prior to WMS 5.5, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wyse_management_suite

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 4d ago at 1 mentions (2026-02-25); latest day: 1
  • 5 total mentions across 5 days

Affected systems

Vendors
Products
wyse_management_suite

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-02-25: 1Mentions · 2026-03-24: 1Mentions · 2026-03-25: 1Mentions · 2026-03-26: 1Mentions · 2026-03-31: 1PoC Mentioned / Linked · 2026-03-24: 1PoC Mentioned / Linked · 2026-03-26: 1Patch / Workaround · 2026-03-25: 1Technical Details · 2026-02-25: 1Technical Details · 2026-03-24: 1Technical Details · 2026-03-25: 1Technical Details · 2026-03-26: 1Technical Details · 2026-03-31: 102-2503-2403-2503-2603-31
Signal classification2 categories
Disclosure
480.0%
PoC
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-251
Disclosure1
2026-03-241
PoC1
2026-03-251
Disclosure1
2026-03-261
Disclosure1
2026-03-311
Disclosure1
Full discourse5 posts
  • Gray Hats@the_yellow_fall
    Disclosure

    A critical RCE chain has been found in Dell Wyse Management Suite (WMS) on-prem. Learn how CVE-2026-22765 and CVE-2026-22766 bypass security in version 5.5. #DellWyse #RCE #CyberSecurity #PT_SWARM #VulnerabilityAlert #Infosec #ThinClient https://meterpreter.org/the-thin-client-trap-how-a-vulnerability-chain-in-dell-wyse-management-suite-unlocks-remote-code-execution/ https://t.co/E1aKnSE9y8

    Post summary

    The post announces the discovery of a critical RCE chain in Dell Wyse Management Suite linked to CVE-2026-22765 and CVE-2026-22766, providing a URL for further details.

    04072608
    10.9K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Dell Wyse Management Suite の 2 件の脆弱性を連鎖:システム全体の侵害につながる恐れ https://iototsecnews.jp/2026/03/24/dell-wyse-management-flaws-could-lead-to-full-system-compromise/ この攻撃の原因は、デバイス登録時の認証不備や API の制限不足といった、複数の小さなロジック欠陥の連鎖にあります。具体的には、脆弱性 CVE-2026-22765 を悪用する攻撃者に対して不適切にトークンが付与され、その後のプロセスで API の直接呼び出しを許すという状況に陥ります。さらに 脆弱性 CVE-2026-22766 の悪用により、特定のプロパティ操作と認証の回避が引き起こされ、RCE につながってしまいます。些細に見える小さな問題であっても、それらが連鎖することで、システム全体の完全侵害を許す深刻な脅威となります。ご利用のチームは、ご注意ください。 #CVE202622765 #CVE202622766 #Dell #Vulnerability #WyseManagementSuite

    Post summary

    The article reports two Dell Wyse Management Suite CVEs that chain through token misuse and API flaws, leading to RCE, but it provides no PoC, exploit code, or patch details.

    01000198
    481 followersView on X
  • Autumn Good@autumn_good_35
    PoC

    🚨🚨🚨 『The final step was chaining all discovered vulnerabilities into an exploit chain, which allowed me to achieve unauthenticated remote code execution (RCE)』 CVE-2026-22765 CVE-2026-22766 unauthenticated RCE in Dell Wyse Management Suite https://swarm.ptsecurity.com/business-logic-and-chains-unauthenticated-rce-in-dell-wyse-management-suite/

    Post summary

    The author demonstrates an exploit chain using CVE-2026-22765 and CVE-2026-22766 to achieve unauthenticated RCE in Dell Wyse Management Suite, but no ready-to-use code is supplied.

    00001411
    6.7K followersView on X
  • CybrPulse@CybrPulse
    Disclosure

    Two Dell Wyse Management Suite flaws chain to unauthenticated RCE. CVE-2026-22765 (CVSS 8.8) gets rogue device to admin; CVE-2026-22766 (CVSS 7.2) uploads a webshell. Patched in WMS 5.5. If you manage Dell thin clients, check your version. https://cybersecuritynews.com/dell-wyse-management-vulnerabilities/ #infosec

    Post summary

    The post announces two unauthenticated RCE vulnerabilities in Dell Wyse Management Suite, supplies CVSS scores, and notes they are patched in version 5.5.

    0000056
    22 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22766 Dell Wyse Management Suite, versions prior to WMS 5.5, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remot… https://www.cve.org/CVERecord?id=CVE-2026-22766

    Post summary

    The text announces CVE‑2026‑22766 as an unrestricted file‑upload vulnerability in Dell Wyse Management Suite versions prior to 5.5, without mentioning PoC, exploit code, active exploitation, or patches.

    00000121
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdellwyse_management_suite---

Explore more