Description
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
Published: 2026-08-19
Score: 4.6 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell OpenManage Enterprise contains a cross‑site scripting vulnerability that allows a low privileged attacker who can reach the web interface to inject script into a generated page. If the attacker succeeds the injected script could read sensitive data from the victim’s session or exfiltrate information, leading to unintended information exposure. The flaw is a classic Improper Neutralization of Input during Web Page Generation weakness, which is a type of input validation problem.

Affected Systems

Dell OpenManage Enterprise versions prior to 4.7.0 are affected. Any system installed with those versions and exposed to remote access is at risk.

Risk and Exploitability

The CVSS score of 4.6 places the vulnerability in the low range. No EPSS score is published, so the likelihood of occurrence is unknown, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that a remote attacker with low privileges who can access the web interface could exploit the flaw to execute the injected script and read confidential data. Proper authorization checks alone do not mitigate the issue, so a patch or other countermeasure is required.

Generated by OpenCVE AI on August 20, 2026 at 03:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell OpenManage Enterprise security update (version 4.7.0 or later).
  • If an immediate update is not possible, restrict Web User Interface access to trusted networks or enforce IP whitelisting.
  • Deploy a web application firewall configured to block reflected XSS payloads targeting the affected pages.

Generated by OpenCVE AI on August 20, 2026 at 03:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Cross‑site scripting leading to information exposure in Dell OpenManage Enterprise

Wed, 19 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell openmanage Enterprise
Vendors & Products Dell
Dell openmanage Enterprise

Wed, 19 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N'}


Subscriptions

Dell Openmanage Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-19T14:10:26.971Z

Reserved: 2026-06-16T05:04:40.992Z

Link: CVE-2026-54793

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-19T15:17:10.757

Modified: 2026-08-19T15:17:10.757

Link: CVE-2026-54793

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T18:00:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')