Description
Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
Published: 2026-08-19
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell OpenManage Enterprise contains a server‑side request forgery flaw that does not require authentication. Based on the description, it is inferred that an attacker who can reach the web interface can cause the server to issue arbitrary outgoing requests, potentially revealing internal network information or data that should remain private. This weakness is categorized as CWE‑918.

Affected Systems

All Dell OpenManage Enterprise installations with a major version earlier than 4.7.0 are vulnerable. The affected product is Dell OpenManage Enterprise, versions prior to 4.7.0.

Risk and Exploitability

The CVSS v3.1 base score of 7.2 flags the vulnerability as high severity, reflecting the confidentiality impact of exposed data. EPSS score is < 1%, indicating a low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation requires remote network access to the OpenManage web service, but no credentials are needed, making the attack vector straightforward for an attacker who can reach the target.

Generated by OpenCVE AI on August 20, 2026 at 16:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dell OpenManage Enterprise to version 4.7.0 or later, which contains the SSRF fix.
  • If an upgrade cannot be performed immediately, restrict public access to the OpenManage web interface by limiting it to a trusted IP address range or implementing network segmentation to isolate the management port from external networks.
  • Configure firewall rules or internal request filtering to block or monitor outbound requests originating from the OpenManage server, thereby mitigating SSRF exploitation until a patch is applied.

Generated by OpenCVE AI on August 20, 2026 at 16:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:dell:openmanage_enterprise:*:*:*:*:*:*:*:*

Thu, 20 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Server‑Side Request Forgery in Dell OpenManage Enterprise Exposes Information

Thu, 20 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated SSRF in Dell OpenManage Enterprise Exposes Server Information

Wed, 19 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated SSRF in Dell OpenManage Enterprise Exposes Server Information

Wed, 19 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell openmanage Enterprise
Vendors & Products Dell
Dell openmanage Enterprise

Wed, 19 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Description Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Dell Openmanage Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-20T15:22:31.568Z

Reserved: 2026-06-16T05:04:40.992Z

Link: CVE-2026-54794

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T14:17:34.040

Modified: 2026-08-21T17:57:39.530

Link: CVE-2026-54794

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T16:30:04Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)