Description
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
Published: 2026-09-17
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Execution
Action: Immediate Patch
AI Analysis

Impact

Dell OpenManage Server Administrator versions earlier than 11.1.0.3 have a Missing Authentication for Critical Function vulnerability (CWE-306). An attacker who can reach the module over the network may invoke privileged functions without providing credentials, which can lead to full remote code execution on the host, compromising confidentiality, integrity, and availability of the affected system.

Affected Systems

Affected products include Dell OpenManage Server Administrator Managed Node for Windows, for RHEL 8.10, for RHEL 9.4, for SLES 15, and for Ubuntu 22.04; all releases prior to 11.1.0.3 are vulnerable.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity, while the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalogue. The attack vector is inferred to be remote network access; an unauthenticated attacker can trigger the vulnerable function from outside the host, potentially executing arbitrary code under the context of the OMSA service.

Generated by OpenCVE AI on September 18, 2026 at 06:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Dell OpenManage Server Administrator to version 11.1.0.3 or later to eliminate the missing authentication flaw.
  • Restrict network traffic to the OMSA listening ports by applying firewall rules or network segmentation so that only trusted hosts can reach the service.
  • If a prompt update cannot be applied immediately, disable unused network interfaces or services that expose OMSA to reduce the attack surface.

Generated by OpenCVE AI on September 18, 2026 at 06:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell openmanage Server Administrator
CPEs cpe:2.3:a:dell:openmanage_server_administrator:*:*:*:*:*:*:*:*
Vendors & Products Dell openmanage Server Administrator

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Dell dell Openmanage Server Administrator Managed Node For Ubuntu 22.04
Dell openmanage Server Administrator Managed Node (patch) For Windows
Vendors & Products Dell
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Dell dell Openmanage Server Administrator Managed Node For Ubuntu 22.04
Dell openmanage Server Administrator Managed Node (patch) For Windows

Fri, 18 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Dell OpenManage Server Administrator

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Dell Openmanage Server Administrator Managed Node For Rhel 8.10 Dell Openmanage Server Administrator Managed Node For Rhel 9.4 Dell Openmanage Server Administrator Managed Node For Sles 15 Dell Openmanage Server Administrator Managed Node For Ubuntu 22.04 Openmanage Server Administrator Openmanage Server Administrator Managed Node (patch) For Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-18T03:55:36.575Z

Reserved: 2026-08-26T20:04:54.733Z

Link: CVE-2026-81475

cve-icon Vulnrichment

Updated: 2026-09-17T12:06:26.243Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T12:18:27.457

Modified: 2026-10-01T16:42:41.900

Link: CVE-2026-81475

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:30:15Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function