CVE-2026-44272: SQL Injection
Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell Wyse Management Suite (WMS)to a version that resolves this vulnerability.Fixed in 2605
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44272?
CVE-2026-44272 has a high severity score of 8.8.
How do I fix CVE-2026-44272?
To fix CVE-2026-44272, upgrade to Dell Wyse Management Suite version 2605 or later.
What type of vulnerability is CVE-2026-44272?
CVE-2026-44272 is an SQL Injection vulnerability.
Who can exploit CVE-2026-44272?
A low privileged attacker with remote access can potentially exploit CVE-2026-44272.
What are the potential consequences of exploiting CVE-2026-44272?
Exploiting CVE-2026-44272 could lead to unauthorized access within the system.