Description
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
Published: 2026-08-19
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell OpenManage Enterprise contains an improper privilege management flaw that can allow a high‑privileged attacker who already has remote access to elevate their privileges. The vulnerability is a classic example of CWE‑269 and, if exploited, would let the attacker gain more authority within the system than intended, potentially leading to full compromise of the managed infrastructure.

Affected Systems

The affected system is Dell OpenManage Enterprise for all versions released prior to 4.7.0. Any instance of this software that has not been updated to 4.7.0 or later is susceptible.

Risk and Exploitability

The CVSS score of 7.2 indicates high severity, while the EPSS score of 0.00316 (less than 1%) indicates a very low probability of exploitation. The lack of a KEV listing suggests no known active exploitation at this time. The likely attack vector is a remote high‑privileged attacker, inferred because the description states remote access is required and the attacker must possess high privileges to successfully abuse the flaw.

Generated by OpenCVE AI on August 20, 2026 at 17:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell security update that raises OpenManage Enterprise to version 4.7.0 or later.
  • Enforce least privilege by restricting remote access to authorized users only and disabling unnecessary privileged accounts.
  • Monitor system and access logs for signs of privilege escalation attempts or anomalous administrative activity.

Generated by OpenCVE AI on August 20, 2026 at 17:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:dell:openmanage_enterprise:*:*:*:*:*:*:*:*

Thu, 20 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Improper Privilege Management Enabling Remote Elevation in Dell OpenManage Enterprise

Thu, 20 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Privilege Management in Dell OpenManage Enterprise

Wed, 19 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Privilege Management in Dell OpenManage Enterprise

Wed, 19 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell openmanage Enterprise
Vendors & Products Dell
Dell openmanage Enterprise

Wed, 19 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Openmanage Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-20T18:30:31.986Z

Reserved: 2026-08-04T11:16:10.499Z

Link: CVE-2026-70421

cve-icon Vulnrichment

Updated: 2026-08-20T18:30:29.013Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T14:17:38.743

Modified: 2026-08-21T17:55:52.453

Link: CVE-2026-70421

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T17:30:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management