Description
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
Published: 2026-08-19
Score: 8.8 High
EPSS: 2.4% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell OpenManage Enterprise versions before 4.7.0 contain a flaw that allows an attacker with low privileges and remote access to inject operating system commands and execute them. The vulnerability is an improper neutralization of special elements in command strings, which can lead to arbitrary command execution and potentially full system compromise. According to the description, the attacker only needs remote access and does not require elevated privileges to trigger the exploit.

Affected Systems

The affected product is Dell OpenManage Enterprise, any installation running a version earlier than 4.7.0. All systems participating in the OpenManage Enterprise management network are susceptible, regardless of the specific deployment size.

Risk and Exploitability

The CVSS score of 8.8 categorizes this issue as high severity, and the EPSS score of 2% indicates a low but non-zero chance of exploitation, while the lack of KEV listing does not diminish the inherent risk. An attacker can exploit the vulnerability remotely over network services provided by OpenManage Enterprise, and the low prerequisite of a low‑privileged account means that many environments could be impacted. Once exploited, the attacker gains the ability to execute arbitrary OS commands, which can compromise confidentiality, integrity, and availability of the affected infrastructure.

Generated by OpenCVE AI on August 20, 2026 at 23:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the Dell OpenManage Enterprise update to version 4.7.0 or later from Dell’s support site
  • Revoke or lock down remote access for low‑privileged accounts and enforce least privilege for OpenManage Enterprise users
  • Enable logging of executed system commands and set up alerts for suspicious activity to detect potential exploitation

Generated by OpenCVE AI on August 20, 2026 at 23:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:dell:openmanage_enterprise:*:*:*:*:*:*:*:*

Thu, 20 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Dell OpenManage Enterprise OS Command Injection Vulnerability (Pre-4.7.0)

Thu, 20 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title Dell OpenManage Enterprise OS Command Injection Vulnerability (Pre-4.7.0)

Thu, 20 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title OS Command Injection Vulnerability in Dell OpenManage Enterprise Versions Prior to 4.7.0

Wed, 19 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Title OS Command Injection Vulnerability in Dell OpenManage Enterprise Versions Prior to 4.7.0

Wed, 19 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell openmanage Enterprise
Vendors & Products Dell
Dell openmanage Enterprise

Wed, 19 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Openmanage Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-20T03:56:13.237Z

Reserved: 2026-06-16T05:04:40.992Z

Link: CVE-2026-54795

cve-icon Vulnrichment

Updated: 2026-08-19T15:33:23.570Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T14:17:34.200

Modified: 2026-08-21T17:57:13.800

Link: CVE-2026-54795

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T23:30:07Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')