Executive brief
Dell OpenManage Server Administrator is a system management tool used to monitor and control enterprise server hardware. This CSRF vulnerability allows an unauthenticated attacker to trick an authenticated user into performing unauthorized actions (like making configuration changes or executing commands), potentially compromising server integrity and security.
Technical details
CVE-2026-80355 is a Cross-Site Request Forgery vulnerability in Dell OpenManage Server Administrator versions prior to 11.1.0.3. An unauthenticated attacker with network access can craft a malicious request that, when executed by an authenticated administrator, performs unauthorized actions without explicit consent. The vulnerability requires user interaction (UI:R) and has a CVSS score of 5.4. The fix is available in version 11.1.0.3 or later.
Affected products
- Dell OpenManage Server Administrator prior to 11.1.0.3
Timeline
- 2026-09-17: disclosed
- 2026-09-17: patched: Version 11.1.0.3 or later