Description
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
Published: 2026-09-17
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access
Action: Immediate Patch
AI Analysis

Impact

Dell OpenManage Server Administrator versions prior to 11.1.0.3 contain a Use of Hard‑coded Credentials flaw. The application stores default credentials that can be used by an attacker to gain unauthorized access. An attacker who can reach the service remotely could authenticate with these predefined credentials, leading to unauthorized control over the server management functions.

Affected Systems

Affected product is Dell OpenManage Server Administrator Managed Node for Windows, RHEL 8.10, RHEL 9.4, SLES 15, and Ubuntu 22.04. All assets running any of these Linux or Windows distributions with OMSA prior to release 11.1.0.3 are vulnerable. Dell recommends updating to the security‑fixed version or later.

Risk and Exploitability

The CVSS score of 7.3 indicates a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog at this time. An unauthenticated attacker with remote access; the attacker can reach the management service over the network. The presence of hard‑coded credentials removes the requirement for legitimate authentication, making the exploit straightforward once network reachability is achieved.

Generated by OpenCVE AI on September 18, 2026 at 07:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Download and install the Dell OpenManage Server Administrator security update (version 11.1.0.3 or later) from Dell's support site.
  • Restrict external network reachability to the OMSA management ports (e.g., via firewall or VLAN) until the patch is applied, to reduce exposure.
  • Ensure that remote management access is allowed only from trusted management stations and enforce strong authentication once the patch is in place.

Generated by OpenCVE AI on September 18, 2026 at 07:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell openmanage Server Administrator
CPEs cpe:2.3:a:dell:openmanage_server_administrator:*:*:*:*:*:*:*:*
Vendors & Products Dell openmanage Server Administrator

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Dell dell Openmanage Server Administrator Managed Node For Ubuntu 22.04
Dell openmanage Server Administrator Managed Node (patch) For Windows
Vendors & Products Dell
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Dell dell Openmanage Server Administrator Managed Node For Ubuntu 22.04
Dell openmanage Server Administrator Managed Node (patch) For Windows

Fri, 18 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Title Hard‑Coded Credentials Allow Remote Unauthorized Access in Dell OpenManage Server Administrator

Thu, 17 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
Weaknesses CWE-798
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Dell Dell Openmanage Server Administrator Managed Node For Rhel 8.10 Dell Openmanage Server Administrator Managed Node For Rhel 9.4 Dell Openmanage Server Administrator Managed Node For Sles 15 Dell Openmanage Server Administrator Managed Node For Ubuntu 22.04 Openmanage Server Administrator Openmanage Server Administrator Managed Node (patch) For Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-17T12:02:26.087Z

Reserved: 2026-08-26T20:04:54.730Z

Link: CVE-2026-81440

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T12:18:27.210

Modified: 2026-10-01T16:50:00.983

Link: CVE-2026-81440

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:30:15Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials