SQL Injection Vulnerability in Dell Wyse Management Suite
CVE-2026-44272
8.8HIGH
What is CVE-2026-44272?
The Dell Wyse Management Suite is susceptible to an SQL injection vulnerability, which arises from improper handling of special elements in SQL commands. This issue affects versions prior to 2605, allowing low privileged attackers to exploit it via remote access. If exploited, the vulnerability could lead to unauthorized access to sensitive information within the management suite, representing a significant risk to organizations utilizing this product.
Affected Version(s)
Wyse Management Suite (WMS) 0 < 2605
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dell would like to thank Duc Luong Tran (janlele91) and Huynh Dinh Vu (WinD39) for reporting this issue.