Threat Advisory

Dell ThinOS Flaws Let Attackers Execute Arbitrary System Commands

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Dell ThinOS 10 is affected by multiple security vulnerabilities, including critical remote code execution flaws in proprietary ThinOS components. The September 2026 security update addresses seven proprietary CVEs along with vulnerabilities in third-party components including Samba, GNU C Library, and jbig2dec. The most severe issues can allow unauthenticated attackers to execute arbitrary code remotely.

CVE-2026-81046 (CVSS 9.4 – Critical): A protection mechanism failure in Dell ThinOS 10 that can be exploited by an unauthenticated remote attacker to achieve arbitrary code execution within the application context.
CVE-2026-81048 (CVSS 9.6 – Critical): A command injection vulnerability that allows an unauthenticated attacker with adjacent network access to execute arbitrary commands remotely.
CVE-2026-81467 (CVSS 9.8 – Critical): An OS command injection vulnerability that can be exploited by an unauthenticated remote attacker to execute commands on the affected ThinOS system.
CVE-2026-81468 (CVSS 9.1 – Critical): An OS command injection vulnerability requiring high privileges that can allow a remote attacker to execute commands.
CVE-2026-81052 (CVSS 6.8 – Medium): A download-of-code-without-integrity-check vulnerability that can allow an unauthenticated attacker with physical access to execute arbitrary code.
CVE-2026-81051 (CVSS 6.6 – Medium): A security version number vulnerability that allows a low-privileged attacker with physical access to bypass protection mechanisms.
CVE-2026-81049 (CVSS 4.4 – Medium): A missing integrity-check vulnerability that can allow a high-privileged local attacker to execute arbitrary code.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Dell ThinOS 10 is affected by multiple security vulnerabilities, including critical remote code execution flaws in proprietary ThinOS components. The September 2026 security update addresses seven proprietary CVEs along with vulnerabilities in third-party components including Samba, GNU C Library, and jbig2dec. The most severe issues can allow unauthenticated attackers to execute arbitrary code remotely.

CVE-2026-81046 (CVSS 9.4 – Critical): A protection mechanism failure in Dell ThinOS 10 that can be exploited by an unauthenticated remote attacker to achieve arbitrary code execution within the application context.
CVE-2026-81048 (CVSS 9.6 – Critical): A command injection vulnerability that allows an unauthenticated attacker with adjacent network access to execute arbitrary commands remotely.
CVE-2026-81467 (CVSS 9.8 – Critical): An OS command injection vulnerability that can be exploited by an unauthenticated remote attacker to execute commands on the affected ThinOS system.
CVE-2026-81468 (CVSS 9.1 – Critical): An OS command injection vulnerability requiring high privileges that can allow a remote attacker to execute commands.
CVE-2026-81052 (CVSS 6.8 – Medium): A download-of-code-without-integrity-check vulnerability that can allow an unauthenticated attacker with physical access to execute arbitrary code.
CVE-2026-81051 (CVSS 6.6 – Medium): A security version number vulnerability that allows a low-privileged attacker with physical access to bypass protection mechanisms.
CVE-2026-81049 (CVSS 4.4 – Medium): A missing integrity-check vulnerability that can allow a high-privileged local attacker to execute arbitrary code.[emaillocker id="1283"]

RECOMMENDATION:

We recommend you to update Dell ThinOS to the 2605_10.2616 or later version.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu