Database/Firmware, BMC & network fabric
Dell OpenManage Enterprise: authenticated low-privilege OS command injection on the management appliance
Impact
A low-privileged remote user of the OpenManage Enterprise console can get commands executed by the appliance. OME is the console that drives iDRAC across a fleet: it holds BMC credentials, pushes firmware and BIOS payloads, and can power-cycle or reconfigure servers. Command execution there is a foothold on the out-of-band management path for every server the appliance manages, which on a GPU estate means the hosts an operator cannot cheaply drain. Dell's record states command execution and does not further detail the reachable command surface.
Who can reach it
Remote network access to the OpenManage Enterprise web interface with a low-privileged console account. Authentication is required, but no administrator role is.
What to do
Upgrade the appliance to OpenManage Enterprise 4.7.0 or later per DSA-2026-359; this is an appliance update and restart, not a host or GPU node outage. Keep the OME interface off general tenant networks and restricted to the management VLAN, and review console accounts - low-privileged ones are the precondition here. Rotate any iDRAC or service credentials the appliance stores if you suspect the console was reached.
References
Related entries
- Linux kernel mlx5_core IPsec offload / eswitch mode interlock: The acquire-SA path unconditionally callsCVE-2026-64522 · Linux kernel mlx5_core IPsec offload / eswitch mode interlockHigh
- MikroTik RouterOS: pre-auth btest session leaks kernel buffer data and can restart the deviceCVE-2026-67277 · MikroTik RouterOS (btest bandwidth test service)High
- Dell OpenManage Enterprise: authenticated SQL injection exposes management database contentsCVE-2026-71176 · Dell OpenManage Enterprise (SQL injection)High
- Linux KVM - intra-host migration/mirroring of SEV-SNP VMs: KVM allowed intra-host migration and mirroring of SEV-SNPCVE-2026-72286 · Linux KVM - intra-host migration/mirroring of SEV-SNP VMsHigh
- Linux kernel (drivers/infiniband/hw/bnxt_re): The variable-WQE send-queue slot count came straight from userspace withCVE-2026-72497 · Linux kernel (drivers/infiniband/hw/bnxt_re)High
- Linux bnxt_re RoCE driver (CQ toggle page use-after-free): The completion-queue variant of the toggle-pageCVE-2026-72499 · Linux bnxt_re RoCE driver (CQ toggle page use-after-free)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.