DSA-2026-389: Security Update for Dell ThinOS 10 for Multiple Vulnerabilities
Summary: Dell ThinOS 10 remediation is available for multiple vulnerabilities that could be exploited by malicious users to compromise the affected system.
Impact
Critical
Details
| Third-party Component | CVEs | More Information |
|---|---|---|
| Samba | CVE-2026-6949, CVE-2026-15779, CVE-2026-58216, CVE-2026-58218, CVE-2026-58221, CVE-2026-58222, CVE-2026-58224 | http://nvd.nist.gov/ |
| GNU C Library | CVE-2026-4046, CVE-2026-4437, CVE-2026-4438, CVE-2026-5435, CVE-2026-5450, CVE-2026-5928, CVE-2026-6238, CVE-2025-15281, CVE-2026-0861, CVE-2026-0915 | http://nvd.nist.gov/ |
| jbig2dec | CVE-2026-38076 | http://nvd.nist.gov/ |
| httplib2 | CVE-2026-59939 | http://nvd.nist.gov/ |
| libXpm | CVE-2026-4367 | http://nvd.nist.gov/ |
| libXfont | CVE-2026-56001, CVE-2026-56002, CVE-2026-56003 | http://nvd.nist.gov/ |
| libde265 | CVE-2024-38949, CVE-2024-38950, CVE-2025-61147, CVE-2026-33164, CVE-2026-33165, CVE-2026-45382, CVE-2026-45383, CVE-2026-49295, CVE-2026-49337, CVE-2026-49346, CVE-2026-54240, CVE-2026-54241 | http://nvd.nist.gov/ |
| libarchive | CVE-2026-5745, CVE-2026-14164 | http://nvd.nist.gov/ |
| Wget | CVE-2026-15146 | http://nvd.nist.gov/ |
| libexif | CVE-2026-32775, CVE-2026-40385, CVE-2026-40386 | http://nvd.nist.gov/ |
| Vim | CVE-2026-59856, CVE-2026-59857, CVE-2026-59858 | http://nvd.nist.gov/ |
| libheif | CVE-2026-47709, CVE-2026-47714 | http://nvd.nist.gov/ |
| PAM | CVE-2026-54411 | http://nvd.nist.gov/ |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2026-81046 | Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Arbitrary Code Execution within the application context. | 9.4 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L |
| CVE-2026-81048 | Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote Code execution | 9.6 | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| CVE-2026-81051 | Dell ThinOS 10, versions prior to 2605_10.2616, contain a Security Version Number Mutable to Older Versions vulnerability. A low privileged attacker with physical access could potentially exploit this vulnerability, leading to Protection mechanism bypass. | 6.6 | CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-81052 | Dell ThinOS 10, versions prior to 2605_10.2616, contain a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to arbitrary code execution. | 6.8 | CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-81049 | Dell ThinOS 10, versions prior to 2605_10.2616, contain a Missing Support for Integrity Check vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution. | 4.4 | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
| CVE-2026-81467 | Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution. | 9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-81468 | Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. | 9.1 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2026-81046 | Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Arbitrary Code Execution within the application context. | 9.4 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L |
| CVE-2026-81048 | Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote Code execution | 9.6 | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| CVE-2026-81051 | Dell ThinOS 10, versions prior to 2605_10.2616, contain a Security Version Number Mutable to Older Versions vulnerability. A low privileged attacker with physical access could potentially exploit this vulnerability, leading to Protection mechanism bypass. | 6.6 | CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-81052 | Dell ThinOS 10, versions prior to 2605_10.2616, contain a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to arbitrary code execution. | 6.8 | CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-81049 | Dell ThinOS 10, versions prior to 2605_10.2616, contain a Missing Support for Integrity Check vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution. | 4.4 | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
| CVE-2026-81467 | Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution. | 9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-81468 | Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. | 9.1 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Affected Products & Remediation
|
Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Release Date (DD/MM/YYYY) |
Link |
|
Latitude 3440 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Latitude 5440 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Latitude 5450 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Latitude 3420 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Latitude 5540 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Latitude 5550 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Latitude 3330 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Latitude 3450 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Latitude 5520 (MHC) |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Latitude 5530 (MHC) |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
OptiPlex 7020 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
OptiPlex All-in-One 7410 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
OptiPlex All-in-One 7420 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
OptiPlex Micro Plus 7010 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
OptiPlex 5400 All-in-One |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
OptiPlex 3000 TC |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Wyse 5070 Thin Client |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Wyse 5070 Extended Thin Client |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Wyse 5470 MTC |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Wyse 5470 All-in-One Thin Client |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell Pro Rugged 13 RA13250 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell Pro Rugged 14 RB14250 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell Pro 16 Plus PB16250 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell Pro 14 PC14250 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell Pro 24 All-in-One |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell Pro 16 PC16250 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell Pro Max 16 Plus |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell Pro Max 14 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell Pro Tower QCT1250 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell Pro Slim Low SFF |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell Precision 3260 Compact |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell Precision 3280 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell Pro 24 All-in-One (65 W) QC24250 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell Pro 24 All-in-One Plus QB24250 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell Pro Micro QCM1250 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell Pro Slim Plus XE5 OEM QBS1250 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell Pro Tower Plus XE5 OEM QBT1250 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell Pro Micro QCM1250 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell Pro Max MicroFCM2250 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell pro micro–Thin Client Q9M1260 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Release Date (DD/MM/YYYY) |
Link |
|
Latitude 3440 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Latitude 5440 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Latitude 5450 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Latitude 3420 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Latitude 5540 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Latitude 5550 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Latitude 3330 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Latitude 3450 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Latitude 5520 (MHC) |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Latitude 5530 (MHC) |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
OptiPlex 7020 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
OptiPlex All-in-One 7410 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
OptiPlex All-in-One 7420 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
OptiPlex Micro Plus 7010 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
OptiPlex 5400 All-in-One |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
OptiPlex 3000 TC |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Wyse 5070 Thin Client |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Wyse 5070 Extended Thin Client |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Wyse 5470 MTC |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Wyse 5470 All-in-One Thin Client |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell Pro Rugged 13 RA13250 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell Pro Rugged 14 RB14250 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell Pro 16 Plus PB16250 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell Pro 14 PC14250 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell Pro 24 All-in-One |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell Pro 16 PC16250 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell Pro Max 16 Plus |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell Pro Max 14 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell Pro Tower QCT1250 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell Pro Slim Low SFF |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell Precision 3260 Compact |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell Precision 3280 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell Pro 24 All-in-One (65 W) QC24250 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell Pro 24 All-in-One Plus QB24250 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell Pro Micro QCM1250 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell Pro Slim Plus XE5 OEM QBS1250 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell Pro Tower Plus XE5 OEM QBT1250 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell Pro Micro QCM1250 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell Pro Max MicroFCM2250 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
|
|
Dell pro micro–Thin Client Q9M1260 |
ThinOS 10 |
Versions prior to 2605_10.2616 |
Version 2605_10.2616 or later |
08/31/2026 |
Revision History
"
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2026-09-09 | Initial Release |
| 2.0 | 2026-09-10 | Added Acknowledgment |
Acknowledgements
CVE-2026-81052: Dell Technologies would like to thank saltedfish for reporting this issue.