CVE-2026-66269

Summary

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.

Affected Software

VendorProductVersion RangeStatus
DellDell OpenManage Server Administrator Managed Node (Patch) for Windows0 < 11.1.0.3affected
DellDell OpenManage Server Administrator Managed Node for RHEL 8.100 < 11.1.0.3affected
DellDell OpenManage Server Administrator Managed Node for RHEL 9.40 < 11.1.0.3affected
DellDell OpenManage Server Administrator Managed Node for SLES 150 < 11.1.0.3affected
DellDell OpenManage Server Administrator Managed Node for Ubuntu 22.040 < 11.1.0.3affected

Weaknesses

  • CWE-470: CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References