Junglewise Threat Intelligence

CVE-2026-81475: Dell OpenManage Server Administrator missing authentication in critical function

CVE-2026-81475 · Severity: high · CVSS 8.1 · Published 2026-09-17

Technologies: Dell OpenManage Server Administrator. Vendors: Dell.

Executive brief

Dell OpenManage Server Administrator is a management tool used to monitor and administer Dell servers. An unauthenticated attacker with remote access could bypass security controls and execute arbitrary code on the server, potentially compromising the entire system and any workloads it hosts.

Technical details

This vulnerability is a missing authentication control on a critical function in Dell OpenManage Server Administrator versions prior to 11.1.0.3 (CVE-2026-81475). The vulnerability allows unauthenticated attackers to access sensitive functionality remotely without providing credentials. An attacker with network access to the OMSA interface can exploit this to achieve remote code execution. The vulnerability has been addressed in version 11.1.0.3 and later through a patch distributed via Dell security advisory DSA-2026-403.

Affected products

  • Dell OpenManage Server Administrator prior to 11.1.0.3

Timeline

  • 2026-09-17: disclosed
  • 2026-09-17: patched: Patch available in version 11.1.0.3

References

Related threats