CVE-2026-81446 PUBLISHED

Assigner: dell
Reserved: 26.08.2026 Published: 17.09.2026 Updated: 17.09.2026

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
CVSS Score: 7.4

Product Status

Vendor Dell
Product OpenManage Server Administrator Managed Node (Patch) for Windows
Versions Default: unaffected
  • affected from 0 to 11.1.0.3 (excl.)
Vendor Dell
Product OpenManage Server Administrator Managed Node for RHEL 8.10
Versions Default: unaffected
  • affected from 0 to 11.1.0.3 (excl.)
Vendor Dell
Product OpenManage Server Administrator Managed Node for RHEL 9.4
Versions Default: unaffected
  • affected from 0 to 11.1.0.3 (excl.)
Vendor Dell
Product OpenManage Server Administrator Managed Node for SLES 15
Versions Default: unaffected
  • affected from 0 to 11.1.0.3 (excl.)
Vendor Dell
Product OpenManage Server Administrator Managed Node for Ubuntu 22.04
Versions Default: unaffected
  • affected from 0 to 11.1.0.3 (excl.)

Credits

  • Dell would like to thank saltedfish for reporting these issues. other

References

Problem Types

  • CWE-918: Server-Side Request Forgery (SSRF) CWE