Database/Control plane, storage & DevOps
Dell OpenManage Enterprise: unauthenticated SSRF reaches services on the management network
Impact
OpenManage Enterprise is the fleet console for PowerEdge servers, including the XE-class GPU chassis, and it normally sits on the management VLAN holding iDRAC credentials and driving firmware, inventory and power operations. An unauthenticated attacker who can reach the console can make it issue requests on their behalf and return information from hosts it can talk to but they cannot. Dell rates the scope as changed with low confidentiality and integrity impact, which fits reading responses from internal endpoints rather than direct takeover. Dell's advisory does not name the affected endpoint or what can be reached, so treat this as reconnaissance depth into the out-of-band network rather than a confirmed path to iDRAC control.
Who can reach it
Anyone who can open a network connection to the OpenManage Enterprise web interface. No authentication and no user interaction required, so exposure depends entirely on whether the console is confined to the management VLAN.
What to do
Upgrade the OpenManage Enterprise appliance to 4.7.0 or later per DSA-2026-359. The upgrade restarts the management appliance only - managed servers keep running, so no GPU node needs to be drained or rebooted. Until the upgrade lands, confirm the console is not reachable from tenant or general corporate networks.
References
Related entries
- Dell OpenManage Enterprise: privileged user can inject OS commands and run code on the applianceCVE-2026-54796 · Dell OpenManage Enterprise (OS command handling)High
- Ivanti Endpoint Manager Mobile: Improper input validationCVE-2026-6973 · Ivanti Endpoint Manager MobileHigh
- Dell OpenManage Enterprise: improper privilege management lets a privileged account escalate furtherCVE-2026-70421 · Dell OpenManage Enterprise (privilege management)High
- Pandora FMS: blind SQL injection through the module parameter of the Grafana datasource endpointCVE-2026-75786 · Pandora FMS (Grafana datasource endpoint, module parameter)High
- MongoDB Server: use-after-free in query memory tracking crashes or corrupts the server processCVE-2026-82061 · MongoDB Server (query execution memory tracking)High
- Airflow FAB provider: deactivated accounts keep working through already-issued API tokensCVE-2026-82310 · Apache Airflow FAB provider (Core API token authentication)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.