{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-81240","assignerOrgId":"c550e75a-17ff-4988-97f0-544cde3820fe","state":"PUBLISHED","assignerShortName":"dell","dateReserved":"2026-08-26T17:05:27.564Z","datePublished":"2026-09-15T17:40:13.659Z","dateUpdated":"2026-09-17T11:57:47.561Z"},"containers":{"cna":{"providerMetadata":{"orgId":"c550e75a-17ff-4988-97f0-544cde3820fe","shortName":"dell","dateUpdated":"2026-09-15T17:40:13.659Z"},"datePublic":"2026-09-15T17:37:00.000Z","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-434","description":"CWE-434: Unrestricted Upload of File with Dangerous Type","type":"CWE"}]}],"affected":[{"vendor":"Dell","product":"Wyse Management Suite","versions":[{"status":"affected","version":"0","lessThan":"WMS 2605.0.3.683","versionType":"semver"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.","supportingMedia":[{"type":"text/html","base64":false,"value":"Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution."}]}],"references":[{"url":"https://www.dell.com/support/kbdoc/en-us/000502744/dsa-2026-387-security-update-for-dell-wyse-management-suite-wms-for-multiple-vulnerabilities","tags":["vendor-advisory"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"LOW","baseSeverity":"HIGH","baseScore":8.6,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L"}}],"credits":[{"lang":"en","value":"Dell would like to thank janlele91 for reporting this issue.","type":"finder"}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 1.0.5"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-16T03:56:56.406428Z","id":"CVE-2026-81240","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-17T11:57:47.561Z"}}]}}