DSA-2026-247: Security Update for Dell Wyse Management Suite (WMS) for Multiple Vulnerabilities
Summary: Dell Wyse Management Suite (WMS) remediation is available for multiple vulnerabilities that may be exploited by malicious users to compromise the affected system.
Impact
High
Details
|
Third-party Component |
CVEs |
More Information |
|
MongoDB |
CVE-2026-4148, CVE-2026-4147 |
|
|
Log4j |
CVE-2026-34480 |
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2026-44272 |
Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. |
8.8 |
|
|
CVE-2026-44271 |
Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. |
8.1 |
|
|
CVE-2026-44274 |
Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Link Resolution Before File Access vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access. |
7.8 |
|
|
CVE-2026-44273 |
Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain a Use of Default Credentials vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure. |
6.0 |
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2026-44272 |
Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. |
8.8 |
|
|
CVE-2026-44271 |
Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. |
8.1 |
|
|
CVE-2026-44274 |
Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Link Resolution Before File Access vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access. |
7.8 |
|
|
CVE-2026-44273 |
Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain a Use of Default Credentials vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure. |
6.0 |
Affected Products & Remediation
|
CVEs Addressed |
Product |
Affected Versions |
Remediated Versions |
Release Date (MM/DD/YYYY) |
Link |
|
CVE-2026-4148, CVE-2026-4147, CVE-2026-34480, CVE-2026-4427, CVE-2026-44271, CVE-2026-44274, CVE-2026-44273 |
Dell Wyse Management Suite (WMS) |
Versions prior to 2605 |
Versions 2605 or later |
06/01/2026 |
|
|
CVE-2026-44274 |
Dell Wyse Management Suite Repository |
Versions prior to 2605 |
Versions 2605 or later |
06/01/2026 |
|
CVEs Addressed |
Product |
Affected Versions |
Remediated Versions |
Release Date (MM/DD/YYYY) |
Link |
|
CVE-2026-4148, CVE-2026-4147, CVE-2026-34480, CVE-2026-4427, CVE-2026-44271, CVE-2026-44274, CVE-2026-44273 |
Dell Wyse Management Suite (WMS) |
Versions prior to 2605 |
Versions 2605 or later |
06/01/2026 |
|
|
CVE-2026-44274 |
Dell Wyse Management Suite Repository |
Versions prior to 2605 |
Versions 2605 or later |
06/01/2026 |
Revision History
"
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2026-06-16 | Initial Release |
Acknowledgements
CVE-2026-44271, CVE-2026-44272: Dell would like to thank Duc Luong Tran (janlele91) and Huynh Dinh Vu (WinD39) for reporting this issue.
CVE-2026-44273: Dell would like to thank Christophe Schleypen - NATO OTAN for reporting this issue.