Junglewise Threat Intelligence

CVE-2026-66269: Dell OpenManage Server Administrator unsafe reflection in network code

CVE-2026-66269 · Severity: high · CVSS 7.3 · Published 2026-09-17

Technologies: Dell OpenManage Server Administrator. Vendors: Dell.

Executive brief

Dell OpenManage Server Administrator is a remote management tool used to monitor and administer Dell servers. CVE-2026-66269 is an unsafe reflection vulnerability that allows unauthenticated attackers on the network to bypass protection mechanisms and gain unauthorized access to the system, potentially compromising server security and data integrity.

Technical details

The vulnerability is a Use of Externally-Controlled Input to Select Classes or Code (CWE-917, unsafe reflection) in Dell OpenManage Server Administrator versions prior to 11.1.0.3. An unauthenticated attacker with network access can exploit this flaw to bypass protection mechanisms and gain unauthorized control. The attack requires no user interaction and no authentication. The vulnerability allows attackers to select and execute arbitrary classes or code paths, leading to information disclosure, integrity compromise, and potential availability impact (CVSS 7.3). A patch is available in version 11.1.0.3 and later.

Affected products

  • Dell OpenManage Server Administrator prior to 11.1.0.3

Timeline

  • 2026-09-17: disclosed: CVE-2026-66269 published
  • 2026-09-17: patched: Update available; advisory DSA-2026-403 released

References

Related threats