Junglewise Threat Intelligence

CVE-2026-80355: Dell OpenManage Server Administrator Cross-Site Request Forgery

CVE-2026-80355 · Severity: medium · CVSS 5.4 · Published 2026-09-17

Technologies: Dell OpenManage Server Administrator. Vendors: Dell.

Executive brief

Dell OpenManage Server Administrator is a system management tool used to monitor and control enterprise server hardware. This CSRF vulnerability allows an unauthenticated attacker to trick an authenticated user into performing unauthorized actions (like making configuration changes or executing commands), potentially compromising server integrity and security.

Technical details

CVE-2026-80355 is a Cross-Site Request Forgery vulnerability in Dell OpenManage Server Administrator versions prior to 11.1.0.3. An unauthenticated attacker with network access can craft a malicious request that, when executed by an authenticated administrator, performs unauthorized actions without explicit consent. The vulnerability requires user interaction (UI:R) and has a CVSS score of 5.4. The fix is available in version 11.1.0.3 or later.

Affected products

  • Dell OpenManage Server Administrator prior to 11.1.0.3

Timeline

  • 2026-09-17: disclosed
  • 2026-09-17: patched: Version 11.1.0.3 or later

References

Related threats