Description
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.
Published: 2026-09-17
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery (SSRF)
Action: Immediate Patch
AI Analysis

Impact

An unauthenticated attacker with remote access to the Dell OpenManage Server Administrator Web interface can exploit a Server‑Side Request Forgery (SSRF) flaw present in versions prior to 11.1.0.3. The flaw allows the attacker to instruct the OMAd service to fetch arbitrary URLs, which can be internal or external. This capability can be used to enumerate internal network services, exfiltrate sensitive information, or potentially trigger internal vulnerabilities, impacting confidentiality and integrity of the managed systems.

Affected Systems

All Dell OpenManage Server Administrator Managed Node installations running Windows, RHEL 8.10, RHEL 9.4, SLES 15, or Ubuntu 22.04 that use a version earlier than 11.1.0.3 are affected. Any deployment of the Managed Node component exposed to remote traffic and lacking authentication protection falls within this scope.

Risk and Exploitability

The CVSS score of 7.4 classifies the issue as high severity. Because the vulnerability is unauthenticated and the exploitation is server‑side, the primary attack vector is network based. Exploit code would be simple once a session is established, but no public exploitation data is currently reported and the vulnerability is not listed in the CISA KEV catalog. The absence of an EPSS score makes precise likelihood assessment difficult, yet the high CVSS suggests a meaningful risk if the interface is reachable from untrusted networks.

Generated by OpenCVE AI on September 17, 2026 at 20:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official Dell patch that upgrades OpenManage Server Administrator Managed Node to version 11.1.0.3 or later.
  • If immediate patching is not possible, configure the operating system or network firewall to restrict inbound access to the OMAd web interface to trusted hosts only.
  • Enable authentication or enforce TLS on the OMAd interface to ensure that only authorized users can trigger internal requests.
  • Monitor server logs for outbound HTTP requests originating from the OMAd service to detect potential misuse.

Generated by OpenCVE AI on September 17, 2026 at 20:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell openmanage Server Administrator
CPEs cpe:2.3:a:dell:openmanage_server_administrator:*:*:*:*:*:*:*:*
Vendors & Products Dell openmanage Server Administrator

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Title Dell OpenManage Server Administrator SSRF Vulnerability Allows Remote Unauthenticated Request Forgery
First Time appeared Dell
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Dell dell Openmanage Server Administrator Managed Node For Ubuntu 22.04
Dell openmanage Server Administrator Managed Node (patch) For Windows
Vendors & Products Dell
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Dell dell Openmanage Server Administrator Managed Node For Ubuntu 22.04
Dell openmanage Server Administrator Managed Node (patch) For Windows

Thu, 17 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N'}


Subscriptions

Dell Dell Openmanage Server Administrator Managed Node For Rhel 8.10 Dell Openmanage Server Administrator Managed Node For Rhel 9.4 Dell Openmanage Server Administrator Managed Node For Sles 15 Dell Openmanage Server Administrator Managed Node For Ubuntu 22.04 Openmanage Server Administrator Openmanage Server Administrator Managed Node (patch) For Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-19T14:21:53.228Z

Reserved: 2026-08-26T20:04:54.730Z

Link: CVE-2026-81446

cve-icon Vulnrichment

Updated: 2026-09-19T14:15:34.602Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T15:16:52.573

Modified: 2026-10-06T16:23:27.520

Link: CVE-2026-81446

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:00:17Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)