Junglewise Threat Intelligence

CVE-2026-81440: Dell OpenManage Server Administrator hard-coded credentials

CVE-2026-81440 · Severity: high · CVSS 7.3 · Published 2026-09-17

Technologies: Dell OpenManage Server Administrator. Vendors: Dell.

Executive brief

Dell OpenManage Server Administrator is a management tool used to configure and monitor Dell servers. This vulnerability contains hard-coded credentials that an attacker can use to gain unauthorized access to affected systems without needing to know the actual admin password. An unauthenticated attacker on the network could potentially gain full administrative control over monitored servers.

Technical details

CVE-2026-81440 is a hard-coded credentials vulnerability in Dell OpenManage Server Administrator versions prior to 11.1.0.3. The vulnerability allows an unauthenticated attacker with remote network access to exploit embedded credentials in the application, leading to unauthorized access and potential compromise of managed systems. The attack vector is network-based with no authentication or user interaction required (CVSS vector: AV:N/AC:L/PR:N/UI:N). An attacker can use these credentials to gain administrative access to the management interface and potentially the underlying infrastructure. Remediation is available through upgrading to version 11.1.0.3 or later.

Affected products

  • Dell OpenManage Server Administrator prior to 11.1.0.3

Timeline

  • 2026-09-17: disclosed

References

Related threats