Junglewise Threat Intelligence

CVE-2026-81446: Dell OpenManage Server Administrator SSRF vulnerability

CVE-2026-81446 · Severity: high · CVSS 7.4 · Published 2026-09-17

Technologies: Dell OpenManage Server Administrator. Vendors: Dell.

Executive brief

Dell OpenManage Server Administrator is a remote management tool used by IT teams to monitor and configure Dell servers. An unauthenticated attacker with network access could exploit a server-side request forgery flaw to make the server perform unauthorized network requests, potentially accessing internal systems, sensitive data, or launching further attacks against the organization's infrastructure.

Technical details

CVE-2026-81446 is a server-side request forgery (SSRF) vulnerability in Dell OpenManage Server Administrator versions before 11.1.0.3. The vulnerability allows an unauthenticated attacker with remote network access to trigger arbitrary HTTP requests from the OMSA server by exploiting improper input validation in request handling. The attack requires user interaction (UI:R) but operates across security boundaries (S:C), allowing an attacker to access internal resources, internal services, or sensitive information that the OMSA server can reach. The patch is available in version 11.1.0.3 and later.

Affected products

  • Dell OpenManage Server Administrator prior to 11.1.0.3

Timeline

  • 2026-09-17: disclosed
  • 2026-09-17: patched: Patch available in version 11.1.0.3

References

Related threats