Description
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
Published: 2026-09-17
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an improper neutralization of special elements used in an OS command, allowing an attacker to inject and execute arbitrary system commands. Because the flaw can be exploited by anyone with remote access and does not require authentication, it potentially leads to full system compromise and loss of confidentiality, integrity, and availability.

Affected Systems

Dell OpenManage Server Administrator Managed Node for Windows, RHEL 8.10, RHEL 9.4, SLES 15, and Ubuntu 22.04. All versions before 11.1.0.3 are affected.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity. The EPSS score is 1%, indicating a very low exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is remote network access to the OpenManage interface, with no authentication required to trigger the command injection.

Generated by OpenCVE AI on September 20, 2026 at 04:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Dell Security Advisory DSA-2026-403 to upgrade OpenManage Server Administrator to version 11.1.0.3 or later.
  • If an immediate upgrade is not possible, restrict external network access to the OpenManage Server Administrator services, allowing only trusted hosts to reach the interface.
  • Implement input validation so that special characters are properly sanitized before executing OS commands, thereby mitigating the underlying command injection flaw.

Generated by OpenCVE AI on September 20, 2026 at 04:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell openmanage Server Administrator
CPEs cpe:2.3:a:dell:openmanage_server_administrator:*:*:*:*:*:*:*:*
Vendors & Products Dell openmanage Server Administrator

Sun, 20 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote OS Command Injection in Dell OpenManage Server Administrator Prior to 11.1.0.3

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Dell dell Openmanage Server Administrator Managed Node For Ubuntu 22.04
Dell openmanage Server Administrator Managed Node (patch) For Windows
Vendors & Products Dell
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Dell dell Openmanage Server Administrator Managed Node For Ubuntu 22.04
Dell openmanage Server Administrator Managed Node (patch) For Windows

Fri, 18 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote OS Command Injection in Dell OpenManage Server Administrator Prior to 11.1.0.3

Fri, 18 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Dell Openmanage Server Administrator Managed Node For Rhel 8.10 Dell Openmanage Server Administrator Managed Node For Rhel 9.4 Dell Openmanage Server Administrator Managed Node For Sles 15 Dell Openmanage Server Administrator Managed Node For Ubuntu 22.04 Openmanage Server Administrator Openmanage Server Administrator Managed Node (patch) For Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-18T03:55:35.125Z

Reserved: 2026-08-26T20:04:54.733Z

Link: CVE-2026-81476

cve-icon Vulnrichment

Updated: 2026-09-17T12:05:00.809Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T12:18:27.580

Modified: 2026-10-01T16:39:43.283

Link: CVE-2026-81476

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:30:18Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')