DSA-2026-403: Security Update for Dell OpenManage Server Administrator (OMSA) Network Access Vulnerabilities
Summary: Dell OpenManage Server Administrator (OMSA) remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
Impact
High
Details
|
Proprietary Code CVE |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2026-66269 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. |
7.3 |
|
|
CVE-2026-80355 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. |
5.4 |
|
|
CVE-2026-80356 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. |
7.3 |
|
|
CVE-2026-81438 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. |
3.7 |
|
|
CVE-2026-81439 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. |
3.7 |
|
|
CVE-2026-81440 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. |
7.3 |
|
|
CVE-2026-81441 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Denial of service. |
4.0 |
|
|
CVE-2026-81442 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering and Unauthorized access. |
8.1 |
|
|
CVE-2026-81443 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery. |
6.4 |
|
|
CVE-2026-81445 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. |
7.2 |
|
|
CVE-2026-81446 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery. |
7.4 |
|
|
CVE-2026-81447 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering. |
6.8 |
|
|
CVE-2026-81453 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. |
6.5 |
|
|
CVE-2026-81474 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
7.8 |
|
|
CVE-2026-81475 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. |
8.1 |
|
|
CVE-2026-81476 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. |
8.1 |
|
|
CVE-2026-81477 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution. |
7.2 |
|
|
CVE-2026-81478 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. |
8.1 |
|
|
CVE-2026-81479 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Partial String Comparison vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service. |
5.8 |
|
|
CVE-2026-81480 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Stack-based Buffer Overflow vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution. |
7.2 |
|
|
CVE-2026-81481 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. |
7.5 |
|
Proprietary Code CVE |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2026-66269 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. |
7.3 |
|
|
CVE-2026-80355 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. |
5.4 |
|
|
CVE-2026-80356 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. |
7.3 |
|
|
CVE-2026-81438 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. |
3.7 |
|
|
CVE-2026-81439 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. |
3.7 |
|
|
CVE-2026-81440 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. |
7.3 |
|
|
CVE-2026-81441 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Denial of service. |
4.0 |
|
|
CVE-2026-81442 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering and Unauthorized access. |
8.1 |
|
|
CVE-2026-81443 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery. |
6.4 |
|
|
CVE-2026-81445 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. |
7.2 |
|
|
CVE-2026-81446 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery. |
7.4 |
|
|
CVE-2026-81447 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering. |
6.8 |
|
|
CVE-2026-81453 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. |
6.5 |
|
|
CVE-2026-81474 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
7.8 |
|
|
CVE-2026-81475 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. |
8.1 |
|
|
CVE-2026-81476 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. |
8.1 |
|
|
CVE-2026-81477 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution. |
7.2 |
|
|
CVE-2026-81478 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. |
8.1 |
|
|
CVE-2026-81479 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Partial String Comparison vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service. |
5.8 |
|
|
CVE-2026-81480 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Stack-based Buffer Overflow vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution. |
7.2 |
|
|
CVE-2026-81481 |
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. |
7.5 |
Affected Products & Remediation
|
Product |
Affected Versions |
Remediated Versions |
Link |
|
Dell OpenManage Server Administrator Managed Node (Patch) for Windows |
Versions prior to 11.1.0.3 |
Version 11.1.0.3 |
https://www.dell.com/support/home/drivers/driversdetails?driverid=9R8RG |
|
Dell OpenManage Server Administrator Managed Node for RHEL 8.10 |
Versions prior to 11.1.0.3 |
Version 11.1.0.3 |
https://www.dell.com/support/home/drivers/driversdetails?driverid=2YM3C |
|
Dell OpenManage Server Administrator Managed Node for RHEL 9.4 |
Versions prior to 11.1.0.3 |
Version 11.1.0.3 |
https://www.dell.com/support/home/drivers/driversdetails?driverid=M28JP |
|
Dell OpenManage Server Administrator Managed Node for SLES 15 |
Versions prior to 11.1.0.3 |
Version 11.1.0.3 |
https://www.dell.com/support/home/drivers/driversdetails?driverid=GFCPF |
|
Dell OpenManage Server Administrator Managed Node for Ubuntu 22.04 |
Versions prior to 11.1.0.3 |
Version 11.1.0.3 |
https://www.dell.com/support/home/drivers/driversdetails?driverid=RF6W7 |
|
Product |
Affected Versions |
Remediated Versions |
Link |
|
Dell OpenManage Server Administrator Managed Node (Patch) for Windows |
Versions prior to 11.1.0.3 |
Version 11.1.0.3 |
https://www.dell.com/support/home/drivers/driversdetails?driverid=9R8RG |
|
Dell OpenManage Server Administrator Managed Node for RHEL 8.10 |
Versions prior to 11.1.0.3 |
Version 11.1.0.3 |
https://www.dell.com/support/home/drivers/driversdetails?driverid=2YM3C |
|
Dell OpenManage Server Administrator Managed Node for RHEL 9.4 |
Versions prior to 11.1.0.3 |
Version 11.1.0.3 |
https://www.dell.com/support/home/drivers/driversdetails?driverid=M28JP |
|
Dell OpenManage Server Administrator Managed Node for SLES 15 |
Versions prior to 11.1.0.3 |
Version 11.1.0.3 |
https://www.dell.com/support/home/drivers/driversdetails?driverid=GFCPF |
|
Dell OpenManage Server Administrator Managed Node for Ubuntu 22.04 |
Versions prior to 11.1.0.3 |
Version 11.1.0.3 |
https://www.dell.com/support/home/drivers/driversdetails?driverid=RF6W7 |
Revision History
|
Revision |
Date |
Description |
|
1.0 |
2026-09-08 |
Initial Release |
Acknowledgements
- CVE-2026-80355, CVE-2026-80356, CVE-2026-81442, CVE-2026-81443, CVE-2026-81445, CVE-2026-81446, CVE-2026-81447, CVE-2026-81453: Dell would like to thank saltedfish for reporting these issues.