Dell TechnologiesCVE-2026-81476
Dell Technologies OpenManage Server: command injection
High8.1CVE-2026-81476 · Published Sep 17, 2026 · updated Sep 18, 2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| OpenManage Server Administrator Managed Node (Patch) for Windows Product | < 11.1.0.3 | 11.1.0.3 |
| OpenManage Server Administrator Managed Node for RHEL 8.10 Product | < 11.1.0.3 | 11.1.0.3 |
| OpenManage Server Administrator Managed Node for RHEL 9.4 Product | < 11.1.0.3 | 11.1.0.3 |
| OpenManage Server Administrator Managed Node for SLES 15 Product | < 11.1.0.3 | 11.1.0.3 |
| OpenManage Server Administrator Managed Node for Ubuntu 22.04 Product | < 11.1.0.3 | 11.1.0.3 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-78
More Dell Technologies advisories
All Dell Technologies| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 17 | Dell Technologies Driver Pack For Linux OS: code execution | High8.2 | Driver Pack For Windows OS 26.07.01+3 more |
| Sep 17 | Dell Technologies OpenManage Server: improper privilege management | High7.2 | 11.1.0.3+2 more |
| Sep 17 | Dell Technologies OpenManage Server: server-side request forgery | High7.4 | 11.1.0.3+2 more |
| Sep 17 | Dell Technologies OpenManage Server: improper certificate validation | Medium6.8 | 11.1.0.3+2 more |
| Sep 17 | Dell Technologies OpenManage Server: information disclosure | High7.3 | 11.1.0.3+2 more |
| Sep 17 | Dell Technologies SmartFabric Manager: information disclosure | Low3.5 | 2.2.1 or later |