Description
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.
Published: 2026-09-17
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a Server‑Side Request Forgery flaw in Dell OpenManage Server Administrator versions before 11.1.0.3. An attacker with low privileged remote access can craft requests that force the server to resolve arbitrary URLs, potentially leaking internal information or enabling further attacks against the internal network.

Affected Systems

The flaw affects all Dell OpenManage Server Administrator Managed Node deployments for Windows, RHEL 8.10, RHEL 9.4, SLES 15, and Ubuntu 22.04 that are running a version earlier than 11.1.0.3.

Risk and Exploitability

The CVSS score of 6.4 indicates medium severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits yet. Based on the description, it is inferred that a low privileged attacker can trigger the SSRF over the network interface exposed by OMSA, and that the risk depends on the exposure of the OMSA management console and the internal resources reachable from it.

Generated by OpenCVE AI on September 17, 2026 at 22:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Dell security update that upgrades OMSA to version 11.1.0.3 or later.
  • Restrict outbound connections from the OMSA server so that it can reach only the required external hosts; block untrusted destinations.
  • Ensure that the account used by OMSA has no unnecessary privileges and runs with the principle of least privilege.
  • If the patch cannot be applied immediately, isolate the OMSA management interface to a trusted network segment or place it behind a firewall that limits access to internal services.

Generated by OpenCVE AI on September 17, 2026 at 22:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell openmanage Server Administrator
CPEs cpe:2.3:a:dell:openmanage_server_administrator:*:*:*:*:*:*:*:*
Vendors & Products Dell openmanage Server Administrator

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Dell dell Openmanage Server Administrator Managed Node For Ubuntu 22.04
Dell openmanage Server Administrator Managed Node (patch) For Windows
Vendors & Products Dell
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Dell dell Openmanage Server Administrator Managed Node For Ubuntu 22.04
Dell openmanage Server Administrator Managed Node (patch) For Windows

Thu, 17 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Dell Dell Openmanage Server Administrator Managed Node For Rhel 8.10 Dell Openmanage Server Administrator Managed Node For Rhel 9.4 Dell Openmanage Server Administrator Managed Node For Sles 15 Dell Openmanage Server Administrator Managed Node For Ubuntu 22.04 Openmanage Server Administrator Openmanage Server Administrator Managed Node (patch) For Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-19T14:21:53.407Z

Reserved: 2026-08-26T20:04:54.730Z

Link: CVE-2026-81443

cve-icon Vulnrichment

Updated: 2026-09-19T14:15:46.884Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T14:17:31.243

Modified: 2026-10-06T16:22:42.963

Link: CVE-2026-81443

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:37:16Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)