Home

Description

Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

PUBLISHED Reserved 2026-05-05 | Published 2026-06-22 | Updated 2026-06-23 | Assigner dell




HIGH: 8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Product status

Default status
unaffected

Any version before 2605
affected

Credits

Dell would like to thank Duc Luong Tran (janlele91) and Huynh Dinh Vu (WinD39) for reporting this issue. finder

References

www.dell.com/support/kbdoc/en-us/000472001/dsa-2026-247 vendor-advisory

cve.org (CVE-2026-44272)

nvd.nist.gov (CVE-2026-44272)

Download JSON