Database/Control plane, storage & DevOps
Dell OpenManage Enterprise: privileged user can inject OS commands and run code on the appliance
Impact
An attacker who already holds a high-privileged OpenManage Enterprise account can get command execution on the management appliance itself, with full confidentiality, integrity and availability impact. That appliance is the machine that stores iDRAC credentials and pushes firmware and BIOS updates to every managed server, so code execution there is a foothold on the out-of-band control path for the whole fleet rather than a single host. On a GPU estate that is the difference between one compromised admin session and an attacker positioned to push firmware to nodes that cannot be drained cheaply. Dell does not identify the injectable parameter, so there is no partial mitigation to apply at the request layer.
Who can reach it
Remote network access to the console plus an account that already carries high privileges in OpenManage Enterprise. This is a privilege-boundary escape for an existing admin or a stolen admin credential, not an entry point for an anonymous attacker.
What to do
Upgrade the appliance to OpenManage Enterprise 4.7.0 or later per DSA-2026-359; no workaround is published. The upgrade restarts the management appliance, leaving managed servers untouched. Also review who holds high-privilege OME roles and rotate the iDRAC and directory credentials the appliance stores if you have reason to suspect the console was already reachable by an untrusted admin.
References
Related entries
- Ivanti Endpoint Manager Mobile: Improper input validationCVE-2026-6973 · Ivanti Endpoint Manager MobileHigh
- Dell OpenManage Enterprise: improper privilege management lets a privileged account escalate furtherCVE-2026-70421 · Dell OpenManage Enterprise (privilege management)High
- Pandora FMS: blind SQL injection through the module parameter of the Grafana datasource endpointCVE-2026-75786 · Pandora FMS (Grafana datasource endpoint, module parameter)High
- MongoDB Server: use-after-free in query memory tracking crashes or corrupts the server processCVE-2026-82061 · MongoDB Server (query execution memory tracking)High
- Airflow FAB provider: deactivated accounts keep working through already-issued API tokensCVE-2026-82310 · Apache Airflow FAB provider (Core API token authentication)High
- ATEN Unizon fleet management platform: Unizon is ATEN's centralized manager for its KVM and PDU fleet. The restoreDBCVE-2026-9777 · ATEN Unizon fleet management platformHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.