Description
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
Published: 2026-08-19
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows a low‑privileged attacker with remote access to send unsanitized input that is incorporated into SQL statements within Dell OpenManage Enterprise. The resulting SQL injection could be leveraged to perform script injection, potentially modifying system configuration or affecting data integrity. The impact is confined to the scope of the vulnerable application but could enable further exploitation if additional privileges are gained.

Affected Systems

Dell OpenManage Enterprise, versions prior to 4.7.0

Risk and Exploitability

The CVSS score of 8.1 indicates high severity, while the EPSS score is < 1%, showing a very low exploitation probability, and the vulnerability is not listed in CISA KEV. It can be exploited remotely by an attacker with low privileges, requiring only remote access to the vulnerable component. It is inferred that no public exploit is known, as no exploit is documented and the EPSS score indicates a low likelihood, and the need for connectivity to the vulnerable system reduces immediate risk, but the high CVSS score warrants timely remediation.

Generated by OpenCVE AI on August 20, 2026 at 16:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dell OpenManage Enterprise to version 4.7.0 or later.
  • If an upgrade is not feasible, limit remote access to the component by applying network segmentation or firewall rules to block low‑privileged connections.
  • Deploy a Web Application Firewall or enforce strict input validation to mitigate SQL injection until the patch is applied.

Generated by OpenCVE AI on August 20, 2026 at 16:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:dell:openmanage_enterprise:*:*:*:*:*:*:*:*

Thu, 20 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title SQL Injection Vulnerability in Dell OpenManage Enterprise Allows Script Injection

Thu, 20 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title Remote SQL Injection in Dell OpenManage Enterprise Enables Script Injection

Wed, 19 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Title Remote SQL Injection in Dell OpenManage Enterprise Enables Script Injection

Wed, 19 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell openmanage Enterprise
Vendors & Products Dell
Dell openmanage Enterprise

Wed, 19 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Description Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H'}


Subscriptions

Dell Openmanage Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-19T15:32:31.616Z

Reserved: 2026-08-04T11:16:10.499Z

Link: CVE-2026-70422

cve-icon Vulnrichment

Updated: 2026-08-19T15:32:26.649Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T14:17:38.897

Modified: 2026-08-21T17:55:26.650

Link: CVE-2026-70422

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T16:15:03Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')