Database/Firmware, BMC & network fabric
Dell SmartFabric Manager: insufficient verification of data authenticity allows privilege elevation
Impact
SmartFabric Manager is the controller for Dell fabric switches, which in an accelerator fleet carry storage and east-west traffic between nodes. A low-privileged remote account can escalate privileges because the product does not sufficiently verify the authenticity of data it accepts. An attacker holding fabric-manager administrative rights can reconfigure switching across the fleet - VLAN and port assignments that separate tenants, or uplinks that carry storage traffic. The advisory covers multiple third-party component issues and does not detail the exact data path.
Who can reach it
A remote attacker with a low-privileged account on SmartFabric Manager. Authentication is required, so exposure depends on who can log in to the fabric management plane - normally restricted to the management VLAN.
What to do
Upgrade Dell SmartFabric Manager to 2.2.1 or later per DSA-2026-317 and restart the management service. This is a management-plane appliance upgrade, not a switch firmware flash, so data-plane forwarding is not interrupted. Keep the SmartFabric Manager interface off any tenant-reachable network and audit low-privileged accounts on it.
References
Related entries
- Dell OpenManage Enterprise: low-privileged remote user can inject SQL into the management consoleCVE-2026-70422 · Dell OpenManage Enterprise (management console, SQL injection)High
- Dell OMSA: improper privilege management lets a low-privileged remote user tamper with the nodeCVE-2026-81442 · Dell OpenManage Server Administrator (privilege management)High
- Dell OMSA: missing authentication on a critical function lets an unauthenticated attacker execute codeCVE-2026-81475 · Dell OpenManage Server Administrator (managed node web/agent service)High
- Dell OMSA: unauthenticated OS command injection gives remote execution on the managed nodeCVE-2026-81476 · Dell OpenManage Server Administrator (managed node service, OS command handling)High
- Dell OMSA: hard-coded cryptographic key allows unauthenticated access to the management agentCVE-2026-81478 · Dell OpenManage Server Administrator (hard-coded cryptographic key)High
- InfiniBand / RoCE memory protection - memory region rkey/lkey namespace and protection domains: The only thing standingNCVD-2021-004-infiniband-roce-memory-protectio · InfiniBand / RoCE memory protection - memory region rkey/lkey namespace and protection domainsHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.