Home

Description

Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.

PUBLISHED Reserved 2026-04-15 | Published 2026-06-02 | Updated 2026-06-03 | Assigner dell




HIGH: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-284: Improper Access Control

Product status

Default status
unaffected

Any version before 2602_10.0765_T10
affected

Credits

Dell would like to thank Brandon Schreiber for reporting this issue. finder

References

www.dell.com/support/kbdoc/en-us/000463678/dsa-2026-214 vendor-advisory

cve.org (CVE-2026-40715)

nvd.nist.gov (CVE-2026-40715)

Download JSON