GPU VulnDB

Database/Firmware, BMC & network fabric

Dell OMSA: externally controlled class selection bypasses a protection mechanism

CVSS 7.3CVE-2026-66269Firmware, BMC & network fabriccurated

Impact

OMSA selects classes or code to load based on input an unauthenticated attacker controls, which Dell reports as a protection-mechanism bypass with low impact across confidentiality, integrity and availability. Unsafe reflection is usually a stepping stone rather than the whole attack - it is the piece that defeats a check standing in front of the other OMSA flaws fixed in the same advisory. Treat it as part of the same patch decision rather than something to weigh alone.

Who can reach it

Network access to the OMSA service on a managed node. No authentication required.

What to do

Upgrade OMSA to 11.1.0.3 or later on every managed node and restart the OMSA services; the same package fixes the other DSA-2026-403 issues.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.