Description
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Denial of service.
Published: 2026-09-17
Score: 4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Potential Denial of Service via Unauthenticated Local Access
Action: Patch Now
AI Analysis

Impact

Dell OpenManage Server Administrator versions prior to 11.1.0.3 contain a missing authentication flaw for a critical function. If an attacker gains local access without valid credentials, they may exploit the flaw and cause a denial of service. The vulnerability could be leveraged to disrupt management services, potentially impacting server availability during critical operations.

Affected Systems

Affected systems include Dell OpenManage Server Administrator Managed Node for Windows, as well as for RHEL 8.10, RHEL 9.4, SLES 15, and Ubuntu 22.04. All installations running a version earlier than 11.1.0.3 are susceptible.

Risk and Exploitability

The CVSS score of 4 indicates low severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. The flaw is exploitable only from a local environment, requiring an attacker to reach the host locally. Even though it is not a remote or widespread exploit, denial of service can affect critical infrastructure if exploited during maintenance or change windows.

Generated by OpenCVE AI on September 17, 2026 at 21:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Dell Security Update KB 000506586 to upgrade OpenManage Server Administrator to 11.1.0.3 or later, and reinstall the application to ensure the patch is active.
  • While awaiting the update, restrict local console and shell access to trusted administrators only to mitigate the unauthenticated local access risk.
  • Implement network segmentation to isolate servers running OpenManage from other critical infrastructure to reduce the impact of a potential denial of service.

Generated by OpenCVE AI on September 17, 2026 at 21:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell openmanage Server Administrator
CPEs cpe:2.3:a:dell:openmanage_server_administrator:*:*:*:*:*:*:*:*
Vendors & Products Dell openmanage Server Administrator

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Dell dell Openmanage Server Administrator Managed Node For Ubuntu 22.04
Dell openmanage Server Administrator Managed Node (patch) For Windows
Vendors & Products Dell
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Dell dell Openmanage Server Administrator Managed Node For Ubuntu 22.04
Dell openmanage Server Administrator Managed Node (patch) For Windows

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Description Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Denial of service.
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Dell Dell Openmanage Server Administrator Managed Node For Rhel 8.10 Dell Openmanage Server Administrator Managed Node For Rhel 9.4 Dell Openmanage Server Administrator Managed Node For Sles 15 Dell Openmanage Server Administrator Managed Node For Ubuntu 22.04 Openmanage Server Administrator Openmanage Server Administrator Managed Node (patch) For Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-17T14:20:14.876Z

Reserved: 2026-08-26T20:04:54.730Z

Link: CVE-2026-81441

cve-icon Vulnrichment

Updated: 2026-09-17T14:20:10.419Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T12:18:27.337

Modified: 2026-10-01T16:47:36.377

Link: CVE-2026-81441

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:37:31Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function