Home

Description

Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access control vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information exposure.

PUBLISHED Reserved 2026-04-15 | Published 2026-06-02 | Updated 2026-06-02 | Assigner dell




MEDIUM: 6.1CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Problem types

CWE-284: Improper Access Control

Product status

Default status
unaffected

Any version before 2602_10.0765_T10
affected

Credits

Dell would like to thank Darren McDonald from AmberWolf finder

Dell would like to thank Christophe Schleypen (NATO Cyber Security Centre – NCSC) for reporting this issue. finder

References

www.dell.com/support/kbdoc/en-us/000463678/dsa-2026-214 vendor-advisory

cve.org (CVE-2026-40713)

nvd.nist.gov (CVE-2026-40713)

Download JSON