Description
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
Published: 2026-08-19
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell OpenManage Enterprise contains an Improper Restriction of XML External Entity Reference vulnerability that allows an attacker to cause the system to resolve and retrieve data from external XML entities. This weakness can expose sensitive information from the server or from networked resources, and is classified as CWE-611.

Affected Systems

Dell OpenManage Enterprise prior to version 4.7.0 is affected. The vulnerability exists in all supported builds before the 4.7.0 release, which includes the older 4.6.x series. Users running those versions should verify that they are in the vulnerable set.

Risk and Exploitability

The CVSS score of 6.5 classifies the vulnerability as a moderate risk. No EPSS score is published, and it is not listed in CISA’s KEV catalog. The attack requires low privileges and remote access to the OpenManage Enterprise web interface. The attacker can supply a crafted XML payload that forces the server to retrieve data from an arbitrary external source, potentially exposing confidential data but does not allow execution of code or denial of service.

Generated by OpenCVE AI on August 19, 2026 at 18:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dell OpenManage Enterprise to version 4.7.0 or later.
  • If upgrading is unavailable, reconfigure the application to disable external entity processing in XML parsers.
  • Limit remote access to the OpenManage Enterprise management interface to trusted IP addresses and enforce role‑based permissions.

Generated by OpenCVE AI on August 19, 2026 at 18:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell openmanage Enterprise
Vendors & Products Dell
Dell openmanage Enterprise

Wed, 19 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Description Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
Weaknesses CWE-611
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Dell Openmanage Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-19T13:53:01.061Z

Reserved: 2026-08-04T11:16:10.499Z

Link: CVE-2026-70423

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-19T14:17:39.037

Modified: 2026-08-19T14:17:39.037

Link: CVE-2026-70423

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T20:00:04Z

Weaknesses
  • CWE-611

    Improper Restriction of XML External Entity Reference