GPU VulnDB

Database/Firmware, BMC & network fabric

Dell OpenManage Integration for Windows Admin Center: OS command injection by a low-privilege remote user

CVSS 8.8CVE-2026-101207Firmware, BMC & network fabriccurated

Impact

This extension is how some operators drive Dell PowerEdge server management - inventory, firmware updates, iDRAC interaction - from a Windows Admin Center gateway. Unsanitized input reaches an OS command, so a low-privilege account with remote access to the gateway gets command execution on the management host. That host typically holds iDRAC credentials and the authority to push firmware to servers, so the practical blast radius is the server fleet behind it, including GPU nodes whose BMCs it manages. Dell scores it 8.8 with no user interaction needed. If you do not use Windows Admin Center for Dell hardware, this does not apply to you.

Who can reach it

A remote, authenticated low-privilege user of the Windows Admin Center gateway running the Dell OpenManage Integration extension - in practice anyone with a foothold on the management network and any account on that gateway.

What to do

Update the OpenManage Integration extension to 3.7.0 or later per Dell DSA-2026-442; this is an extension update on the management gateway and a service restart there, with no impact on managed servers and no firmware flash or node reboot. Until it is applied, restrict who can authenticate to the Windows Admin Center gateway and keep it off any network a tenant can reach.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.