Database/Control plane, storage & DevOps
Dell OpenManage Server Administrator (relative path traversal): A low-privileged remote attacker reads arbitrary files
CVSS 6.5CVE-2026-56794Control plane, storage & DevOpscurated
Impact
A low-privileged remote attacker reads arbitrary files from the server hosting OMSA.
Who can reach it
Authenticated low-privilege network access to OMSA below 11.1.0.2.
What to do
Upgrade OMSA to 11.1.0.2, or remove the agent if unused.
References
Related entries
- Apache Airflow: JSON Variable secrets shown in cleartext in the Rendered Templates viewCVE-2026-59244 · Apache Airflow secrets masker (Rendered Templates view, var.json dict values)Medium
- Apache Airflow: masker misses team-prefixed config sections, exposing team Celery broker URLs with credentialsCVE-2026-65017 · Apache Airflow (secrets masker, team-scoped config sections in multi-team mode)Medium
- Airflow Google provider: team scope dropped in Secret Manager backend, so one team resolves another's credentialsCVE-2026-68868 · Apache Airflow Google provider (Google Cloud Secret Manager secrets backend, team scoping)Medium
- Apache Airflow Yandex provider (Lockbox secrets backend, team-scope lookup): When the team-scoped lookup for aCVE-2026-68871 · Apache Airflow Yandex provider (Lockbox secrets backend, team-scope lookup)Medium
- Airflow Amazon provider: AWS secrets backends fall through to a team-agnostic lookup, leaking other teams' credentialsCVE-2026-68872 · Apache Airflow Amazon provider (SSM Parameter Store / Secrets Manager backends)Medium
- Airflow: bulk Variable and Connection endpoints write secrets to the audit log in cleartextCVE-2026-68969 · Apache Airflow (audit-log masking on bulk Variables/Connections endpoints)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.