CVE-2026-81476
8.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Summary
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Dell | OpenManage Server Administrator Managed Node (Patch) for Windows | 0 < 11.1.0.3 | affected |
| Dell | OpenManage Server Administrator Managed Node for RHEL 8.10 | 0 < 11.1.0.3 | affected |
| Dell | OpenManage Server Administrator Managed Node for RHEL 9.4 | 0 < 11.1.0.3 | affected |
| Dell | OpenManage Server Administrator Managed Node for SLES 15 | 0 < 11.1.0.3 | affected |
| Dell | OpenManage Server Administrator Managed Node for Ubuntu 22.04 | 0 < 11.1.0.3 | affected |
Weaknesses
- CWE-78: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.