← Vulnerability feed

Vulnerability record · CVE-2026-40715 · published 2 June 2026

CVE-2026-40715: Dell thinos improper access control vulnerability

Dell · Thinos

Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.

7.8 CVSS 3.1 High EPSS 0.14% · top 97.4% CWE-284 · Improper access control
7.8CVSS 3.1 base score
0.14%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
22 Jul 2026Last modified by NVD

Description

Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-40715 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-81467Dell thinos os command injection vulnerabilityDell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection…EPSS 3.0%9.8CVE-2025-43728Dell thinos vulnerabilityDell ThinOS 10, versions prior to 2508_10.0127, contain a Protection Mechanism Failure vulnerability. An unauthenticated attacker with remote access …EPSS 0.35%9.4CVE-2026-81046Dell thinos improper access control vulnerabilityDell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability. An unauthenticated attacker with remote access …EPSS 0.55%8.8CVE-2026-81048Dell thinos command injection vulnerabilityDell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulner…EPSS 2.4%8.4CVE-2024-53290Dell thinos command injection vulnerabilityDell ThinOS version 2408 contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenti…EPSS 0.83%7.8CVE-2026-61419Dell thinos improper access control vulnerabilityDell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A low privileged attacker with local access could p…EPSS 0.14%7.8CVE-2026-23862Dell thinos command injection vulnerabilityDell ThinOS 10 versions prior to ThinOS 2602_10.0573, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') …EPSS 0.44%7.8CVE-2025-43730Dell thinos argument injection vulnerabilityDell ThinOS 10, versions prior to 2508_10.0127, contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulner…EPSS 0.22%

Source: NIST National Vulnerability Database (record CVE-2026-40715), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.