Description
Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
Published: 2026-08-19
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell OpenManage Enterprise contains a server‑side request forgery flaw that does not require authentication. An attacker who can reach the web interface can cause the server to issue arbitrary outgoing requests, potentially revealing internal network information or data that should remain private. This weakness is categorized as CWE‑918.

Affected Systems

All Dell OpenManage Enterprise installations with a major version earlier than 4.7.0 are vulnerable. The affected product is Dell OpenManage Enterprise, versions prior to 4.7.0.

Risk and Exploitability

The CVSS v3.1 base score of 7.2 flags the vulnerability as high severity, reflecting the confidentiality impact of exposed data. EPSS information is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires remote network access to the OpenManage web service, but no credentials are needed, making the attack vector straightforward for an attacker who can reach the target.

Generated by OpenCVE AI on August 19, 2026 at 18:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dell OpenManage Enterprise to version 4.7.0 or later, which contains the SSRF fix.
  • If an upgrade cannot be performed immediately, restrict public access to the OpenManage web interface by limiting it to a trusted IP address range or implementing network segmentation to isolate the management port from external networks.
  • Configure firewall rules or internal request filtering to block or monitor outbound requests originating from the OpenManage server, thereby mitigating SSRF exploitation until a patch is applied.

Generated by OpenCVE AI on August 19, 2026 at 18:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated SSRF in Dell OpenManage Enterprise Exposes Server Information

Wed, 19 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell openmanage Enterprise
Vendors & Products Dell
Dell openmanage Enterprise

Wed, 19 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Description Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Dell Openmanage Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-19T14:05:26.189Z

Reserved: 2026-06-16T05:04:40.992Z

Link: CVE-2026-54794

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-19T14:17:34.040

Modified: 2026-08-19T14:17:34.040

Link: CVE-2026-54794

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T18:45:03Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)