Description
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a heap‑based buffer overflow that can be triggered by writing beyond a memory boundary during a management command. This flaw permits a low‑privileged local user to overwrite control data, potentially allowing the attacker to execute arbitrary code with higher privileges. The impact is that an attacker who gains local access can elevate privileges on the affected machine, compromising the confidentiality, integrity, or availability of the system.

Affected Systems

The flaw affects Dell OpenManage Server Administrator Managed Node for Windows and for various Linux distributions, including RHEL 8.10, RHEL 9.4, SLES 15, and Ubuntu 22.04, in versions prior to 11.1.0.3. Dell publishes a security update that addresses the vulnerability, shipping under the identifier DSA‑2026‑403.

Risk and Exploitability

The CVSS score of 7.8 indicates a moderate to high severity, but the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Because the attacker must have local, low‑privileged access, the attack vector is limited and the exploitation would require the attacker to be on the system. Nonetheless, the combination of a buffer overflow and privilege escalation is still considered a serious security risk, especially in environments where local administrators cannot be fully trusted.

Generated by OpenCVE AI on September 18, 2026 at 06:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Dell’s security update DSA‑2026‑403 to upgrade OpenManage Server Administrator to at least version 11.1.0.3.
  • If a timely update is not yet possible, remove or disable the affected OpenManage Server Administrator service on systems that are not required to provide local management access.
  • Restrict local user privileges to the minimum necessary, ensuring that users who are given a local account do not have unnecessary shell or command execution rights.

Generated by OpenCVE AI on September 18, 2026 at 06:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell openmanage Server Administrator
CPEs cpe:2.3:a:dell:openmanage_server_administrator:*:*:*:*:*:*:*:*
Vendors & Products Dell openmanage Server Administrator

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Dell dell Openmanage Server Administrator Managed Node For Ubuntu 22.04
Dell openmanage Server Administrator Managed Node (patch) For Windows
Vendors & Products Dell
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Dell dell Openmanage Server Administrator Managed Node For Ubuntu 22.04
Dell openmanage Server Administrator Managed Node (patch) For Windows

Fri, 18 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Title Heap-Based Buffer Overflow in Dell OpenManage Server Administrator Enables Local Privilege Escalation

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Weaknesses CWE-122
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Dell Openmanage Server Administrator Managed Node For Rhel 8.10 Dell Openmanage Server Administrator Managed Node For Rhel 9.4 Dell Openmanage Server Administrator Managed Node For Sles 15 Dell Openmanage Server Administrator Managed Node For Ubuntu 22.04 Openmanage Server Administrator Openmanage Server Administrator Managed Node (patch) For Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-18T03:55:37.996Z

Reserved: 2026-08-26T20:04:54.733Z

Link: CVE-2026-81474

cve-icon Vulnrichment

Updated: 2026-09-17T12:09:02.154Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T11:17:03.077

Modified: 2026-10-01T16:53:48.763

Link: CVE-2026-81474

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:37:45Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow