Database/Control plane, storage & DevOps
Dell OpenManage Server Administrator (improper authentication): An unauthenticated remote attacker gets unauthorized
CVE-2026-56793Control plane, storage & DevOpscurated
Impact
An unauthenticated remote attacker gets unauthorized access to OMSA - the in-band management agent that runs on the server itself, with hardware-level visibility and control.
Who can reach it
Unauthenticated network access to OMSA below 11.1.0.2.
What to do
Upgrade OMSA to 11.1.0.2. Host agent update plus service restart. If you manage servers exclusively out-of-band via iDRAC/Redfish, removing OMSA is the better answer than patching it.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.