Executive brief
Dell OpenManage Server Administrator is a management tool used to monitor and administer Dell servers. An unauthenticated attacker with remote access could bypass security controls and execute arbitrary code on the server, potentially compromising the entire system and any workloads it hosts.
Technical details
This vulnerability is a missing authentication control on a critical function in Dell OpenManage Server Administrator versions prior to 11.1.0.3 (CVE-2026-81475). The vulnerability allows unauthenticated attackers to access sensitive functionality remotely without providing credentials. An attacker with network access to the OMSA interface can exploit this to achieve remote code execution. The vulnerability has been addressed in version 11.1.0.3 and later through a patch distributed via Dell security advisory DSA-2026-403.
Affected products
- Dell OpenManage Server Administrator prior to 11.1.0.3
Timeline
- 2026-09-17: disclosed
- 2026-09-17: patched: Patch available in version 11.1.0.3