Executive brief
Dell OpenManage Server Administrator is a management tool used to monitor and administer Dell servers. An unauthenticated remote attacker can exploit a path traversal vulnerability to read or access arbitrary files on the affected system, potentially exposing sensitive configuration data, credentials, or other critical information stored on the server.
Technical details
CVE-2026-81481 is a path traversal vulnerability (CWE-22: Improper Limitation of a Pathname to a Restricted Directory) in Dell OpenManage Server Administrator versions prior to 11.1.0.3. An unauthenticated attacker with network access can exploit this flaw by crafting malicious requests containing traversal sequences (e.g., "../") to bypass directory restrictions and access files outside the intended restricted directory. This allows filesystem access and information disclosure. The vulnerability requires only network connectivity and no authentication or user interaction. A patch is available in version 11.1.0.3 and later.
Affected products
- Dell OpenManage Server Administrator prior to 11.1.0.3
Timeline
- 2026-09-17: disclosed
- 2026-09-17: patched: Fix available in version 11.1.0.3 and later