Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2336 articles · 160855 vulns · 36/41 feeds (7d)
← Back to list
7.8
CVE-2026-40715PATCHED
dell · thinos

CVE-2026-40715: Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access Control vulnerability. A low privile

Description

Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.

Affected Products

VendorProductVersions
dellthinos0

References

  • https://www.dell.com/support/kbdoc/en-us/000463678/dsa-2026-214(vendor-advisory)

Related News (1 articles)

Tier C
VulDB5d ago
CVE-2026-40715 | Dell ThinOS 10 10.0765 access control (dsa-2026-214)
→ No new info (linked only)
CVSS 3.17.8 HIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
2602_10.0765_T10
CWECWE-284
PublishedJun 2, 2026
Last enriched5d agov2
Trending Score16
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2025-46638
CVE-2025-46638: Dell BSAFE SSL-J contains an allocation of resources without limits or throttling vulnerability. An unauthenticated remo
Trending: 24
PRE-CVE
Multiple Vulnerabilities in Dell Products Including Dell Private Cloud, PowerSwitch Z9864F-ON, Dell Automation Platform, and Dell VxRail Appliance
Trending: 20
MEDIUMCVE-2026-40713EXP
CVE-2026-40713: Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access control vulnerability. An unauthenti
Trending: 19
MEDIUMCVE-2026-35070
CVE-2026-35070: Dell SmartFabric Storage Software, versions prior to 1.4.5, contains an Improper Neutralization of Special Elements used
Trending: 8
NONECVE-2026-9489EXP
NitroSense V3: Local Privilege Escalation (LPE) vulnerability
Trending: 5

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 2, 2026
Discovered by ZDM
Jun 2, 2026
Updated: severity
Jun 2, 2026
Patch Available
Jun 3, 2026

Version History

v2
Last enriched 5d ago
v2Tier C5d ago

Updated severity to CRITICAL and corrected exploit availability to false.

severity
via VulDB
v15d ago

Initial creation