CVE-2026-80355 PUBLISHED

Assigner: dell
Reserved: 26.08.2026 Published: 17.09.2026 Updated: 18.09.2026

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
CVSS Score: 5.4

Product Status

Vendor Dell
Product OpenManage Server Administrator Managed Node (Patch) for Windows
Versions Default: unaffected
  • affected from 0 to 11.1.0.3 (excl.)
Vendor Dell
Product OpenManage Server Administrator Managed Node for RHEL 8.10
Versions Default: unaffected
  • affected from 0 to 11.1.0.3 (excl.)
Vendor Dell
Product OpenManage Server Administrator Managed Node for RHEL 9.4
Versions Default: unaffected
  • affected from 0 to 11.1.0.3 (excl.)
Vendor Dell
Product OpenManage Server Administrator Managed Node for SLES 15
Versions Default: unaffected
  • affected from 0 to 11.1.0.3 (excl.)
Vendor Dell
Product OpenManage Server Administrator Managed Node for Ubuntu 22.04
Versions Default: unaffected
  • affected from 0 to 11.1.0.3 (excl.)

Credits

  • Dell would like to thank saltedfish for reporting these issues. other

References

Problem Types

  • CWE-352: Cross-Site Request Forgery (CSRF) CWE