Description
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.
Published: 2026-09-17
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Assess Impact
AI Analysis

Impact

Dell OpenManage Server Administrator versions prior to 11.1.0.3 contain an Incorrect Authorization flaw that allows an attacker with low privileges and remote access to bypass protection mechanisms, potentially escalating privileges.

Affected Systems

Affected systems are Dell OpenManage Server Administrator Managed Node on Windows, RHEL 8.10, RHEL 9.4, SLES 15, and Ubuntu 22.04, all running versions earlier than 11.1.0.3.

Risk and Exploitability

The CVSS score of 3.7 indicates a low severity impact. With no EPSS score available and no listing in CISA KEV, the likelihood of public exploitation is currently unknown, but the remote nature of the attack vector allows a low‑privileged attacker to exploit the authorization flaw when remote access to the management interface is permitted.

Generated by OpenCVE AI on September 17, 2026 at 21:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Dell security update and upgrade Dell OpenManage Server Administrator to version 11.1.0.3 or later on all affected systems.
  • Configure firewall or network segmentation to restrict remote access to the management interface to trusted privileged users only.
  • Perform an audit of the authorization logic on the management console to ensure that least‑privilege controls are correctly implemented.

Generated by OpenCVE AI on September 17, 2026 at 21:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell openmanage Server Administrator
CPEs cpe:2.3:a:dell:openmanage_server_administrator:*:*:*:*:*:*:*:*
Vendors & Products Dell openmanage Server Administrator

Thu, 17 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title OpenManage Server Administrator Remote Authorization Bypass

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Dell dell Openmanage Server Administrator Managed Node For Ubuntu 22.04
Dell openmanage Server Administrator Managed Node (patch) For Windows
Vendors & Products Dell
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Dell dell Openmanage Server Administrator Managed Node For Ubuntu 22.04
Dell openmanage Server Administrator Managed Node (patch) For Windows

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N'}


Subscriptions

Dell Dell Openmanage Server Administrator Managed Node For Rhel 8.10 Dell Openmanage Server Administrator Managed Node For Rhel 9.4 Dell Openmanage Server Administrator Managed Node For Sles 15 Dell Openmanage Server Administrator Managed Node For Ubuntu 22.04 Openmanage Server Administrator Openmanage Server Administrator Managed Node (patch) For Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-17T14:28:20.636Z

Reserved: 2026-08-26T20:04:54.730Z

Link: CVE-2026-81439

cve-icon Vulnrichment

Updated: 2026-09-17T14:28:13.716Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T11:17:02.957

Modified: 2026-10-01T17:03:31.290

Link: CVE-2026-81439

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:15:14Z

Weaknesses