Executive brief
Dell OpenManage Server Administrator is a remote management platform used to monitor and control Dell servers in enterprise data centers. A low-privileged attacker with network access could exploit a server-side request forgery (SSRF) flaw to make the server perform unauthorized HTTP requests to internal or external systems, potentially accessing sensitive internal resources, APIs, or other servers on the network.
Technical details
CVE-2026-81443 is a Server-Side Request Forgery (SSRF) vulnerability in Dell OpenManage Server Administrator versions prior to 11.1.0.3. A low-privileged remote attacker with valid credentials can exploit this flaw to trigger arbitrary HTTP requests from the vulnerable server to internal or external targets. The vulnerability requires network access and valid authentication (PR:L), and allows an attacker to compromise confidentiality and integrity of internal systems (C:L/I:L). The fix is available in OpenManage Server Administrator version 11.1.0.3 and later.
Affected products
- Dell OpenManage Server Administrator prior to 11.1.0.3
Timeline
- 2026-09-17: disclosed