CVE-2026-81467
Summary
| CVE | CVE-2026-81467 |
|---|---|
| State | PUBLISHED |
| Assigner | dell |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-10 16:17:58 UTC |
| Updated | 2026-09-16 20:47:19 UTC |
| Description | Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution. |
Risk And Classification
Primary CVSS: v3.1 9.8 CRITICAL from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.038410000 probability, percentile 0.895870000 (date 2026-09-16)
Problem Types: CWE-78 | CWE-78 CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Dell | Latitude 3330 | - | All | All | All |
| Hardware | Dell | Latitude 3420 | - | All | All | All |
| Hardware | Dell | Latitude 3440 | - | All | All | All |
| Hardware | Dell | Latitude 3450 | - | All | All | All |
| Hardware | Dell | Latitude 5440 | - | All | All | All |
| Hardware | Dell | Latitude 5450 | - | All | All | All |
| Hardware | Dell | Latitude 5520 | - | All | All | All |
| Hardware | Dell | Latitude 5530 | - | All | All | All |
| Hardware | Dell | Latitude 5540 | - | All | All | All |
| Hardware | Dell | Latitude 5550 | - | All | All | All |
| Hardware | Dell | Optiplex 3000 Tc | - | All | All | All |
| Hardware | Dell | Optiplex 5400 All-in-one | - | All | All | All |
| Hardware | Dell | Optiplex 7020 | - | All | All | All |
| Hardware | Dell | Optiplex All-in-one 7410 | - | All | All | All |
| Hardware | Dell | Optiplex All-in-one 7420 | - | All | All | All |
| Hardware | Dell | Optiplex Micro Plus 7010 | - | All | All | All |
| Hardware | Dell | Precision 3260 Compact | - | All | All | All |
| Hardware | Dell | Precision 3280 | - | All | All | All |
| Hardware | Dell | Pro 14 Pc14250 | - | All | All | All |
| Hardware | Dell | Pro 16 Pc16250 | - | All | All | All |
| Hardware | Dell | Pro 16 Plus Pb16250 | - | All | All | All |
| Hardware | Dell | Pro 24 All-in-one | - | All | All | All |
| Hardware | Dell | Pro 24 All-in-one Plus Qb24250 | - | All | All | All |
| Hardware | Dell | Pro 24 All-in-one 65w Qc24250 | - | All | All | All |
| Hardware | Dell | Pro Max 14 | - | All | All | All |
| Hardware | Dell | Pro Max 16 Plus | - | All | All | All |
| Hardware | Dell | Pro Max Microfcm2250 | - | All | All | All |
| Hardware | Dell | Pro Micro-thin Client Q9m1260 | - | All | All | All |
| Hardware | Dell | Pro Micro Qcm1250 | - | All | All | All |
| Hardware | Dell | Pro Rugged 13 Ra13250 | - | All | All | All |
| Hardware | Dell | Pro Rugged 14 Rb14250 | - | All | All | All |
| Hardware | Dell | Pro Slim Low Sff | - | All | All | All |
| Hardware | Dell | Pro Slim Plus Xe5 Oem Qbs1250 | - | All | All | All |
| Hardware | Dell | Pro Tower Plus Xe5 Oem Qbt1250 | - | All | All | All |
| Hardware | Dell | Pro Tower Qct1250 | - | All | All | All |
| Operating System | Dell | Thinos | All | All | All | All |
| Hardware | Dell | Wyse 5070 Extended Thin Client | - | All | All | All |
| Hardware | Dell | Wyse 5070 Thin Client | - | All | All | All |
| Hardware | Dell | Wyse 5470 All-in-one Thin Client | - | All | All | All |
| Hardware | Dell | Wyse 5470 Mtc | - | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.dell.com/support/kbdoc/en-us/000502746/dsa-2026-389-security-update-fo... | [email protected] | www.dell.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.