Description
Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker.
Published: 2026-08-07
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell OpenManage Server Administrator versions before 11.1.0.2 contain a relative path traversal flaw (CWE-23). A low‑privileged attacker who can reach the OMSA network service may traverse directories outside the intended filesystem boundaries, potentially reading or modifying system files. This threatens both confidentiality and integrity of the host system.

Affected Systems

Dell OpenManage Server Administrator Managed Node for Windows, RHEL 8.10, RHEL 9.4, and SLES 15 are affected when installed with a release earlier than 11.1.0.2, as documented in Dell’s security bulletin.

Risk and Exploitability

The CVSS score is 6.5, indicating moderate severity; the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, implying no confirmed exploitation yet. Nonetheless, the flaw is remotely exploitable by an adversary with only low privileges, providing filesystem access if the OMSA service is reachable. Organizations with OMSA exposed to untrusted networks face a moderate to high risk and should address it promptly.

Generated by OpenCVE AI on August 7, 2026 at 13:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell‑released patch that updates Dell OpenManage Server Administrator to version 11.1.0.2 or newer.
  • If an immediate patch is infeasible, restrict network access to the OMSA service so that only trusted hosts can communicate with it.
  • Disable or remove OMSA components that are not required for your environment to reduce the attack surface.

Generated by OpenCVE AI on August 7, 2026 at 13:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 08 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell dell Openmanage Server Administrator Managed Node (patch) For Windows
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Vendors & Products Dell
Dell dell Openmanage Server Administrator Managed Node (patch) For Windows
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15

Fri, 07 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Title Dell OpenManage Server Administrator Relative Path Traversal Allowing Remote Filesystem Access

Fri, 07 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Description Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker.
Weaknesses CWE-23
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Dell Dell Openmanage Server Administrator Managed Node (patch) For Windows Dell Openmanage Server Administrator Managed Node For Rhel 8.10 Dell Openmanage Server Administrator Managed Node For Rhel 9.4 Dell Openmanage Server Administrator Managed Node For Sles 15 Openmanage Server Administrator
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-07T13:15:11.266Z

Reserved: 2026-06-23T05:04:35.872Z

Link: CVE-2026-56794

cve-icon Vulnrichment

Updated: 2026-08-07T13:15:07.808Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-07T13:16:52.633

Modified: 2026-08-08T00:39:32.573

Link: CVE-2026-56794

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-08T20:41:06Z

Weaknesses
  • CWE-23

    Relative Path Traversal