Description
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.
Published: 2026-09-17
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Protection Mechanism Bypass
Action: Immediate Patch
AI Analysis

Impact

Dell OpenManage Server Administrator versions prior to 11.1.0.3 contain a vulnerability that allows externally controlled input to select classes or code. An unauthenticated attacker with remote access can exploit this flaw, enabling the attacker to bypass built‑in protection mechanisms. The advisory states the impact as a protection mechanism bypass; it does not explicitly confirm code execution or system compromise, so the full extent of damage must be assessed by the affected organization.

Affected Systems

The vulnerability affects Dell OpenManage Server Administrator Managed Node for Windows, for RHEL 8.10, RHEL 9.4, SLES 15, and Ubuntu 22.04. Any deployment running a version earlier than 11.1.0.3 is susceptible. Users should review the installed version and update accordingly.

Risk and Exploitability

The CVSS score of 7.3 indicates high severity. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation documented yet. Because the flaw can be triggered by an unauthenticated remote attacker with direct access to the service, and it involves unsafe reflection, it is inferred that this flaw could allow malicious code injection or bypass of runtime protections, potentially leading to further compromise depending on system configuration and exposure.

Generated by OpenCVE AI on September 17, 2026 at 22:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Dell OpenManage Server Administrator 11.1.0.3 or later on all affected nodes.
  • After applying the update, restrict remote management services to trusted networks and enforce strong authentication.
  • Review and tighten any custom configurations that expose the management interface to the open internet, ensuring that only authorized users can access management functions.

Generated by OpenCVE AI on September 17, 2026 at 22:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell openmanage Server Administrator
CPEs cpe:2.3:a:dell:openmanage_server_administrator:*:*:*:*:*:*:*:*
Vendors & Products Dell openmanage Server Administrator

Thu, 17 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Title Protection Mechanism Bypass via Unsafe Reflection in Dell OpenManage Server Administrator

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell dell Openmanage Server Administrator Managed Node (patch) For Windows
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Vendors & Products Dell
Dell dell Openmanage Server Administrator Managed Node (patch) For Windows
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.
Weaknesses CWE-470
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Dell Dell Openmanage Server Administrator Managed Node (patch) For Windows Dell Openmanage Server Administrator Managed Node For Rhel 8.10 Dell Openmanage Server Administrator Managed Node For Rhel 9.4 Dell Openmanage Server Administrator Managed Node For Sles 15 Openmanage Server Administrator
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-17T14:29:59.884Z

Reserved: 2026-07-24T11:04:27.160Z

Link: CVE-2026-66269

cve-icon Vulnrichment

Updated: 2026-09-17T14:29:45.390Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T11:17:02.693

Modified: 2026-10-06T15:13:11.680

Link: CVE-2026-66269

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T22:30:17Z

Weaknesses
  • CWE-470

    Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')