Description
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
Published: 2026-09-17
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Elevation of Privileges
Action: Apply Patch
AI Analysis

Impact

Dell OpenManage Server Administrator versions before 11.1.0.3 contain an improper privilege management flaw that allows a high‑privileged attacker with remote access to elevate privileges. The vulnerability arises from weaknesses in how the product handles user privilege levels, leading to unauthorized escalation and potential full system compromise.

Affected Systems

The flaw affects Dell OpenManage Server Administrator Managed Node products for Windows, RHEL 8.10, RHEL 9.4, SLES 15, and Ubuntu 22.04. Versions prior to 11.1.0.3 are impacted; later releases contain the fix.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity, and, though EPSS is not available, the absence from the CISA KEV catalog suggests no confirmed exploits yet. The likely attack vector requires remote access and an attacker already holding limited but elevated privileges, leveraging the privilege mismanagement to gain full control.

Generated by OpenCVE AI on September 17, 2026 at 20:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install Dell’s 11.1.0.3 or later patch for OpenManage Server Administrator to address the privilege escalation flaw
  • Limit remote administrative access by disabling unnecessary services or IP filtering, ensuring only trusted hosts can reach the management interface
  • Enforce the principle of least privilege by removing superuser rights from non‑admin accounts and regularly review account permissions

Generated by OpenCVE AI on September 17, 2026 at 20:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell openmanage Server Administrator
CPEs cpe:2.3:a:dell:openmanage_server_administrator:*:*:*:*:*:*:*:*
Vendors & Products Dell openmanage Server Administrator

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Dell dell Openmanage Server Administrator Managed Node For Ubuntu 22.04
Dell openmanage Server Administrator Managed Node (patch) For Windows
Vendors & Products Dell
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Dell dell Openmanage Server Administrator Managed Node For Ubuntu 22.04
Dell openmanage Server Administrator Managed Node (patch) For Windows

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Dell Openmanage Server Administrator Managed Node For Rhel 8.10 Dell Openmanage Server Administrator Managed Node For Rhel 9.4 Dell Openmanage Server Administrator Managed Node For Sles 15 Dell Openmanage Server Administrator Managed Node For Ubuntu 22.04 Openmanage Server Administrator Openmanage Server Administrator Managed Node (patch) For Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-18T03:55:50.936Z

Reserved: 2026-08-26T20:04:54.730Z

Link: CVE-2026-81445

cve-icon Vulnrichment

Updated: 2026-09-17T15:21:45.503Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T15:16:52.447

Modified: 2026-10-06T16:23:10.923

Link: CVE-2026-81445

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:48:11Z

Weaknesses
  • CWE-269

    Improper Privilege Management