Description
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
Published: 2026-08-19
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell OpenManage Enterprise contains an improper neutralization of special elements used in an OS command, known as OS Command Injection. A high privileged attacker with remote access can trigger the vulnerability to execute arbitrary commands on the host, compromising confidentiality, integrity, and availability. The flaw is classified under CWE-78.

Affected Systems

The affected product is Dell OpenManage Enterprise, with any version prior to 4.7.0. The vulnerability appears in deployments that expose remote management interfaces to high privileged users, across all supported operating system platforms that run the software.

Risk and Exploitability

The CVSS score of 7.2 indicates high severity. The exploitation probability is unknown due to missing EPSS data, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is inferred to be remote, as the vulnerability requires remote access to the management console by a high privileged user. Attackers who meet these conditions could gain command execution privileges without additional authentication or local access.

Generated by OpenCVE AI on August 19, 2026 at 17:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dell OpenManage Enterprise to version 4.7.0 or later, which contains the fix for the OS Command Injection issue.
  • If an upgrade is not immediately feasible, limit remote management access to trusted administrators and enforce strict network segmentation to reduce the attack surface.
  • Enable and monitor system logs for anomalous command execution activity, and investigate any suspicious events promptly.

Generated by OpenCVE AI on August 19, 2026 at 17:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title OpenManage Enterprise Vulnerability Allows Remote OS Command Execution

Wed, 19 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell openmanage Enterprise
Vendors & Products Dell
Dell openmanage Enterprise

Wed, 19 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Description Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Openmanage Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-19T14:39:03.818Z

Reserved: 2026-06-16T05:04:40.992Z

Link: CVE-2026-54796

cve-icon Vulnrichment

Updated: 2026-08-19T13:51:08.854Z

cve-icon NVD

Status : Received

Published: 2026-08-19T14:17:34.360

Modified: 2026-08-19T15:17:10.883

Link: CVE-2026-54796

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T18:00:05Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')