Description
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker.
Published: 2026-09-17
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote File System Access
Action: Immediate Patch
AI Analysis

Impact

An improper limitation of a pathname to a restricted directory exists in Dell OpenManage Server Administrator versions prior to 11.1.0.3. The flaw, also known as path traversal, allows a remote attacker who does not need to authenticate to read or write files outside the intended directory. If exploited, the attacker can gain access to sensitive configuration files or system binaries with the permissions of the OpenManage Server Administrator process, leading to potential data disclosure.

Affected Systems

Dell OpenManage Server Administrator Managed Node for Windows, RHEL 8.10, RHEL 9.4, SLES 15, and Ubuntu 22.04 are affected, specifically any installation of the product with a version earlier than 11.1.0.3.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, and the attack vector is remote with no authentication required. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the high impact score and the nature of the flaw suggest that attackers could readily target systems without credentials and read restricted files.

Generated by OpenCVE AI on September 18, 2026 at 06:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Dell Security Update for OpenManage Server Administrator, which upgrades the product to at least version 11.1.0.3, as published on Dell's support site.
  • Restrict remote access to the OpenManage Server Administrator Managed Node service by configuring firewall rules or network segmentation so that only trusted management networks can reach the service during the remediation period.
  • If the security update cannot be applied immediately, enforce stricter file system permissions on the directories used by OMSA to prevent non‑privileged users from reading sensitive files, and monitor for any anomalous file access attempts.

Generated by OpenCVE AI on September 18, 2026 at 06:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell openmanage Server Administrator
CPEs cpe:2.3:a:dell:openmanage_server_administrator:*:*:*:*:*:*:*:*
Vendors & Products Dell openmanage Server Administrator

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Dell dell Openmanage Server Administrator Managed Node For Ubuntu 22.04
Dell openmanage Server Administrator Managed Node (patch) For Windows
Vendors & Products Dell
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Dell dell Openmanage Server Administrator Managed Node For Ubuntu 22.04
Dell openmanage Server Administrator Managed Node (patch) For Windows

Fri, 18 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Title Improper Pathname Restriction Enables Remote File System Access in Dell OpenManage Server Administrator

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker.
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Dell Dell Openmanage Server Administrator Managed Node For Rhel 8.10 Dell Openmanage Server Administrator Managed Node For Rhel 9.4 Dell Openmanage Server Administrator Managed Node For Sles 15 Dell Openmanage Server Administrator Managed Node For Ubuntu 22.04 Openmanage Server Administrator Openmanage Server Administrator Managed Node (patch) For Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-17T19:22:38.939Z

Reserved: 2026-08-26T20:04:54.733Z

Link: CVE-2026-81481

cve-icon Vulnrichment

Updated: 2026-09-17T17:06:21.725Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T13:16:48.350

Modified: 2026-10-02T14:13:13.147

Link: CVE-2026-81481

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:37:25Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')