CVE-2026-81476

Summary

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

Affected Software

VendorProductVersion RangeStatus
DellOpenManage Server Administrator Managed Node (Patch) for Windows0 < 11.1.0.3affected
DellOpenManage Server Administrator Managed Node for RHEL 8.100 < 11.1.0.3affected
DellOpenManage Server Administrator Managed Node for RHEL 9.40 < 11.1.0.3affected
DellOpenManage Server Administrator Managed Node for SLES 150 < 11.1.0.3affected
DellOpenManage Server Administrator Managed Node for Ubuntu 22.040 < 11.1.0.3affected

Weaknesses

  • CWE-78: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References