CVE-2026-49506Patch(dell / wyse_management_suite)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch dell wyse_management_suite systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wyse_management_suite

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • Peaked 1d ago at 2 mentions (2026-06-29); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
wyse_management_suite

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-29: 2Mentions · 2026-07-06: 1Patch / Workaround · 2026-06-29: 2Patch / Workaround · 2026-07-06: 1Technical Details · 2026-06-29: 2Technical Details · 2026-07-06: 106-2907-06
Signal classification1 categories
Patch
3100.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-06-292
Patch2
2026-07-061
Patch1
Full discourse3 posts
  • iototsecnews@iototsecnews
    Patch

    Dell Wyse Management の深刻な脆弱性 CVE-2026-41120/49506 が FIX:RCE の恐れ https://iototsecnews.jp/2026/06/29/critical-dell-wyse-management-suite-vulnerabilities-let-attackers-execute-remote-code/ Dell WMS の問題の背景にあるのは、多くの端末を 1 箇所で統括する仕組みの不備です。脆弱性 CVE-2026-41120/CVE-2026-49506 が放置されると、ネットワークの要となる管理基盤が乗っ取られ、配下のすべてのデバイスへと被害が広がる危険性があります。外部からの不正な命令を受け入れたり、本来見られない内部領域を覗かれたりすることで、組織のシステム全体が稼働停止に追い込まれるなど、きわめて深刻な結果を招きます。確実な防衛策として、開発元が提供している最新の修正プログラムを適用し、システムへの経路を制限することが大切です。日頃からアクセス権を最小限に絞り、おかしな挙動がないか見守る体制を整える必要もあります。 #CVE202641120 #CVE202649506 #Dell #Vulnerability #WyseManagement

    Post summary

    Dell Wyse Management Suite is vulnerable to CVE-2026-41120/49506, potentially enabling remote code execution; applying vendor patches and enforcing least privilege mitigates the threat.

    01000231
    500 followersView on X
  • TECHEPAGES@techepages
    Patch

    🖥️ Dell patched two critical flaws in Wyse Management Suite: CVE-2026-41120 (CVSS 9.8, no auth needed) and CVE-2026-49506 (CVSS 7.2, path traversal) - both capable of remote code execution on enterprise thin-client systems. 🔧 Fix is live in WMS 5.5 HF1 (released May 8) — patch now, as unpatched/internet-exposed instances face heightened risk.

    Post summary

    Dell has released a patch (WMS 5.5 HF1) for CVE-2026-41120 and CVE-2026-49506, which expose remote code execution via no authentication and path traversal, respectively, and urges immediate remediation.

    0000099
    21 followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Dell's Wyse Management Suite has critical vulnerabilities (CVE-2026-41120, CVE-2026-49506) allowing remote code execution. Organizations should update to version 5.5 HF1 immediately to mitigate risks to enterprise networks. #Dell #Wyse #CyberSecurity #Vulnerabilities #RemoteCodeExecution #PatchNow https://thedailytechfeed.com/critical-vulnerabilities-in-dell-wyse-management-suite-allow-remote-code-execution/

    Post summary

    Dell’s Wyse Management Suite is affected by CVE-2026-41120 and CVE-2026-49506, both enabling remote code execution; customers are instructed to apply the 5.5 HF1 patch immediately to mitigate the risk.

    00000111
    442 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appdellwyse_management_suite---
Appdellwyse_management_suite5.5--

Explore more