Description
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering and Unauthorized access.
Published: 2026-09-17
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation and Unauthorized Access
Action: Immediate Patch
AI Analysis

Impact

Dell OpenManage Server Administrator versions prior to 11.1.0.3 contain an Improper Privilege Management flaw. A low‑privileged attacker with remote access can exploit the issue to modify stored information and gain unauthorized access to protected resources.

Affected Systems

The vulnerable products are Dell OpenManage Server Administrator Managed Node for Windows, RHEL 8.10, RHEL 9.4, SLES 15, and Ubuntu 22.04. Any instance running a version earlier than 11.1.0.3 is affected; no further version granularity is provided.

Risk and Exploitability

The vulnerability has a CVSS score of 8.1, indicating high severity. EPSS information is not available and the flaw is not listed in the CISA KEV catalog. An attacker needs low‑privileged credentials coupled with remote access to the OpenManage service to exploit the weakness, which is categorized as CWE‑269 (Improper Privilege Management).

Generated by OpenCVE AI on September 17, 2026 at 20:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Dell security update DSA‑2026‑403 that upgrades OpenManage Server Administrator to version 11.1.0.3 or later.
  • Restrict network exposure of the OpenManage service by isolating vulnerable nodes from remote network access or placing them behind a firewall.
  • Reduce privilege levels for user accounts that interact with OMSA to a minimum necessary level.

Generated by OpenCVE AI on September 17, 2026 at 20:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell openmanage Server Administrator
CPEs cpe:2.3:a:dell:openmanage_server_administrator:*:*:*:*:*:*:*:*
Vendors & Products Dell openmanage Server Administrator

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Title Improper Privilege Management in Dell OpenManage Server Administrator Enables Unauthorized Access
First Time appeared Dell
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Dell dell Openmanage Server Administrator Managed Node For Ubuntu 22.04
Dell openmanage Server Administrator Managed Node (patch) For Windows
Vendors & Products Dell
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Dell dell Openmanage Server Administrator Managed Node For Ubuntu 22.04
Dell openmanage Server Administrator Managed Node (patch) For Windows

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering and Unauthorized access.
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

Dell Dell Openmanage Server Administrator Managed Node For Rhel 8.10 Dell Openmanage Server Administrator Managed Node For Rhel 9.4 Dell Openmanage Server Administrator Managed Node For Sles 15 Dell Openmanage Server Administrator Managed Node For Ubuntu 22.04 Openmanage Server Administrator Openmanage Server Administrator Managed Node (patch) For Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-17T15:37:58.502Z

Reserved: 2026-08-26T20:04:54.730Z

Link: CVE-2026-81442

cve-icon Vulnrichment

Updated: 2026-09-17T15:37:23.504Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T14:17:31.120

Modified: 2026-10-06T16:22:28.353

Link: CVE-2026-81442

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:00:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management