Database/Control plane, storage & DevOps
Dell OpenManage Enterprise: improper privilege management lets a privileged account escalate further
Impact
A high-privileged OpenManage Enterprise user can elevate beyond the role they were assigned, with full confidentiality, integrity and availability impact on the console. In a datacenter that splits OME duties - a firmware operator, a monitoring-only role, a full administrator - this collapses that separation, and the top of that hierarchy controls firmware push and power operations for every managed server. Dell's description does not say which roles or which operation is involved, so the exact starting role is unknown. Fixed in the same release as the other two OME issues, so it does not warrant its own maintenance window.
Who can reach it
Remote network access to the console with an account that already holds high privileges in OpenManage Enterprise. Not exploitable by an unauthenticated attacker.
What to do
Upgrade the appliance to OpenManage Enterprise 4.7.0 or later per DSA-2026-359, which also covers CVE-2026-54794 and CVE-2026-54796. The upgrade restarts the management appliance only; managed servers are unaffected. No workaround is published.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.