Database/Control plane, storage & DevOps
Dell OpenManage Server Administrator (improper authentication): An unauthenticated remote attacker gets unauthorized
CVSS 7.7CVE-2026-56793Control plane, storage & DevOpscurated
Impact
An unauthenticated remote attacker gets unauthorized access to OMSA - the in-band management agent that runs on the server itself, with hardware-level visibility and control.
Who can reach it
Unauthenticated network access to OMSA below 11.1.0.2.
What to do
Upgrade OMSA to 11.1.0.2. Host agent update plus service restart. If you manage servers exclusively out-of-band via iDRAC/Redfish, removing OMSA is the better answer than patching it.
References
Related entries
- Ansible AWX: notification backends allow SSRF from the control node and leak webhook credentialsCVE-2026-71366 · Ansible AWX notification backends (webhook, Mattermost, Rocket.Chat, Grafana)High
- Grafana Alloy: ServiceMonitor bearerTokenFile reads any file and ships it to an attacker scrape targetCVE-2026-75889 · Grafana Alloy (prometheus.operator.servicemonitors component)High
- Ansible automation-controller: survey length-validation error leaks a stored password in plaintextCVE-2026-84499 · Red Hat Ansible Automation Platform automation-controller (survey password validation error)High
- GitLab EE: Duo AI troubleshooting exposes CI/CD variable values from debug job tracesCVE-2026-92470 · GitLab EE (Duo AI troubleshooting access to debug-mode job traces)High
- GlusterFS (brick, mknod): Mknod can create device nodes that point at real devices on the storage server, so a clientCVE-2018-10923 · GlusterFS (brick, mknod)High
- HashiCorp Vault: GCP secrets engine drops existing IAM Conditions when creating/updating rolesetsCVE-2023-5077 · HashiCorp VaultHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.