Description
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker.
Published: 2026-09-17
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Filesystem Access (Path Traversal)
Action: Patch Now
AI Analysis

Impact

The Dell OpenManage Server Administrator software contains an Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) flaw in versions prior to 11.1.0.3. A low‑privileged attacker with remote access can exploit this to read or write arbitrary files on the system, granting filesystem access to the attacker.

Affected Systems

The vulnerability affects Dell OpenManage Server Administrator Managed Node for Windows, RHEL 8.10, RHEL 9.4, SLES 15, and Ubuntu 22.04. All installations running a version below 11.1.0.3 are impacted.

Risk and Exploitability

The CVSS score is 6.5, placing the risk in the medium range. Because the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the likelihood of exploitation is uncertain, but the remote attack vector and low privilege requirement mean that an attacker able to reach the OpenManage interface could execute the path traversal. Immediate patching is recommended to eliminate the exposure.

Generated by OpenCVE AI on September 17, 2026 at 22:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Dell OpenManage Server Administrator update to version 11.1.0.3 or later from Dell support or your package manager.
  • Restrict network access to the OpenManage services by configuring firewall rules or IP allow lists to limit connections to trusted hosts.
  • Enable audit logging for file access on the OpenManage service and review logs for anomalous activity.

Generated by OpenCVE AI on September 17, 2026 at 22:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell openmanage Server Administrator
CPEs cpe:2.3:a:dell:openmanage_server_administrator:*:*:*:*:*:*:*:*
Vendors & Products Dell openmanage Server Administrator

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Dell dell Openmanage Server Administrator Managed Node For Ubuntu 22.04
Dell openmanage Server Administrator Managed Node (patch) For Windows
Vendors & Products Dell
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Dell dell Openmanage Server Administrator Managed Node For Ubuntu 22.04
Dell openmanage Server Administrator Managed Node (patch) For Windows

Thu, 17 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Title Path Traversal in Dell OpenManage Server Administrator Allows Remote Filesystem Access

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Description Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker.
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Dell Dell Openmanage Server Administrator Managed Node For Rhel 8.10 Dell Openmanage Server Administrator Managed Node For Rhel 9.4 Dell Openmanage Server Administrator Managed Node For Sles 15 Dell Openmanage Server Administrator Managed Node For Ubuntu 22.04 Openmanage Server Administrator Openmanage Server Administrator Managed Node (patch) For Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-17T19:20:17.852Z

Reserved: 2026-08-26T20:04:54.731Z

Link: CVE-2026-81453

cve-icon Vulnrichment

Updated: 2026-09-17T17:10:20.803Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T14:17:31.367

Modified: 2026-10-06T16:22:50.850

Link: CVE-2026-81453

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:37:10Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')