Description
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.
Published: 2026-09-17
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Exposure
Action: Patch
AI Analysis

Impact

Dell OpenManage Server Administrator, versions preceding 11.1.0.3, has a vulnerability that permits an exposure of sensitive information to an unauthorized local actor. The flaw can be exploited by an attacker with low‑privileged local access, enabling them to view information they should not be able to see. The weakness is identified as a CWE-200 type flaw, which undermines confidentiality and could reveal configuration details or other sensitive data.

Affected Systems

The affected products are Dell OpenManage Server Administrator Managed Node for Windows, RHEL 8.10, RHEL 9.4, SLES 15, and Ubuntu 22.04. All installations running a version earlier than 11.1.0.3 are susceptible to this issue.

Risk and Exploitability

The CVSS score of 7.3 indicates a high severity scenario. The EPSS score is not currently available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local, requiring low‑privileged attacker access; therefore, the primary risk is information disclosure from the managed node to an unprivileged user.

Generated by OpenCVE AI on September 17, 2026 at 20:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the Dell security update that upgrades OpenManage Server Administrator Managed Node to version 11.1.0.3 or later.
  • Ensure all managed node installations have been updated to the fixed version.
  • Restrict local administrator privileges by limiting low‑privileged user rights to prevent local exploitation.

Generated by OpenCVE AI on September 17, 2026 at 20:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell openmanage Server Administrator
CPEs cpe:2.3:a:dell:openmanage_server_administrator:*:*:*:*:*:*:*:*
Vendors & Products Dell openmanage Server Administrator

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Dell dell Openmanage Server Administrator Managed Node For Ubuntu 22.04
Dell openmanage Server Administrator Managed Node (patch) For Windows
Vendors & Products Dell
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Dell dell Openmanage Server Administrator Managed Node For Ubuntu 22.04
Dell openmanage Server Administrator Managed Node (patch) For Windows

Thu, 17 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title Information Disclosure via Local Access in Dell OpenManage Server Administrator

Thu, 17 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Dell Dell Openmanage Server Administrator Managed Node For Rhel 8.10 Dell Openmanage Server Administrator Managed Node For Rhel 9.4 Dell Openmanage Server Administrator Managed Node For Sles 15 Dell Openmanage Server Administrator Managed Node For Ubuntu 22.04 Openmanage Server Administrator Openmanage Server Administrator Managed Node (patch) For Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-17T15:26:27.602Z

Reserved: 2026-08-26T10:04:27.589Z

Link: CVE-2026-80356

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T15:16:51.973

Modified: 2026-10-06T16:22:58.240

Link: CVE-2026-80356

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:48:07Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor