Executive brief
Dell OpenManage Server Administrator is a remote management tool used to configure and monitor Dell servers. A command injection vulnerability allows an unauthenticated attacker with network access to execute arbitrary operating system commands on affected servers, potentially leading to complete system compromise and unauthorized control of critical infrastructure.
Technical details
CVE-2026-81476 is an OS command injection vulnerability in Dell OpenManage Server Administrator versions prior to 11.1.0.3, caused by improper neutralization of special elements in OS commands. An unauthenticated attacker with network access (no authentication required) can exploit this vulnerability to achieve remote code execution. The vulnerability allows direct command execution at the OS level, giving attackers the ability to fully compromise the affected system. A patch is available in version 11.1.0.3 and later.
Affected products
- Dell OpenManage Server Administrator prior to 11.1.0.3
Timeline
- 2026-09-17: disclosed
- 2026-09-17: patched: Fixed in version 11.1.0.3