Description
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
Published: 2026-08-19
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell OpenManage Enterprise versions prior to 4.7.0 contain an improper neutralisation of special elements used in SQL commands. The flaw, classified as a classic SQL injection (CWE‑89), allows a low‑privileged attacker with remote access to inject malicious SQL statements. If successful, the attacker can cause the database to execute unintended commands, potentially leading to script injection, thereby compromising confidentiality, integrity and availability of the management system.

Affected Systems

All deployments of Dell OpenManage Enterprise running versions earlier than 4.7.0 are affected. The product is accessed through a web interface and RESTful API; thus, any environment exposing these endpoints to external networks is at risk.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.1. The EPSS score is 0.0026 (indicating a very low exploitation probability), and the issue is not listed in the CISA KEV catalog. The likely attack vector is remote via the product’s web interface and RESTful API, inferred from the description that a low‑privileged attacker with remote access could exploit the vulnerability. The flaw requires only low‑privileged credentials and could be attempted from outside the protected network if the management interface is reachable.

Generated by OpenCVE AI on August 20, 2026 at 17:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dell OpenManage Enterprise to version 4.7.0 or later
  • Restrict network access to the OpenManage Enterprise web interface to trusted networks or implement firewall rules that block the interface from untrusted subnets
  • Apply security hardening measures such as disabling unused services, enforcing multi‑factor authentication for administrative accounts, and auditing user activity

Generated by OpenCVE AI on August 20, 2026 at 17:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:dell:openmanage_enterprise:*:*:*:*:*:*:*:*

Thu, 20 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Title SQL Injection in Dell OpenManage Enterprise Enables Script Injection

Thu, 20 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title SQL Injection Vulnerability in Dell OpenManage Enterprise Before 4.7.0

Wed, 19 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title SQL Injection Vulnerability in Dell OpenManage Enterprise Before 4.7.0

Wed, 19 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell openmanage Enterprise
Vendors & Products Dell
Dell openmanage Enterprise

Wed, 19 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L'}


Subscriptions

Dell Openmanage Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-20T15:57:11.018Z

Reserved: 2026-06-18T17:04:56.016Z

Link: CVE-2026-56088

cve-icon Vulnrichment

Updated: 2026-08-20T15:53:09.131Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T14:17:34.517

Modified: 2026-08-21T17:56:37.493

Link: CVE-2026-56088

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T17:15:04Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')