Junglewise Threat Intelligence

CVE-2026-81478: Dell OpenManage Server Administrator hard-coded cryptographic key

CVE-2026-81478 · Severity: high · CVSS 8.1 · Published 2026-09-17

Technologies: Dell OpenManage Server Administrator. Vendors: Dell.

Executive brief

Dell OpenManage Server Administrator is a remote management tool used to monitor and configure Dell servers. A hard-coded cryptographic key in versions prior to 11.1.0.3 allows unauthenticated remote attackers to bypass security controls and gain unauthorized access to the management interface, potentially compromising the confidentiality and integrity of managed infrastructure.

Technical details

CVE-2026-81478 is a hard-coded cryptographic key vulnerability in Dell OpenManage Server Administrator versions before 11.1.0.3. An unauthenticated attacker with network access can exploit this weakness to decrypt protected communications or forge authentication tokens, bypassing authentication mechanisms entirely. The vulnerability requires no user interaction and no prior authentication. Successful exploitation grants unauthorized access to the management interface, allowing an attacker to reconfigure systems, extract sensitive data, or launch further attacks. Dell has released patches in version 11.1.0.3 and later.

Affected products

  • Dell OpenManage Server Administrator prior to 11.1.0.3

Timeline

  • 2026-09-17: disclosed

References

Related threats