GPU VulnDB

Database/Firmware, BMC & network fabric

Dell OMSA: CSRF in the server management web interface can lead to remote execution

CVSS 5.4CVE-2026-80355Firmware, BMC & network fabriccurated

Impact

OMSA is the in-band server management agent fleets use to read hardware health and change platform settings. An unauthenticated attacker who can get an administrator's browser to load a crafted page can drive OMSA actions as that administrator, and Dell states the outcome can reach remote execution. On a GPU fleet that means platform-level changes or command execution on the host under the management agent's privileges, against the same nodes that are expensive to drain. Exploitation needs an admin to visit attacker content while authenticated to OMSA, which is the normal pattern for operators who keep the OMSA console open.

Who can reach it

Remote and unauthenticated as far as the attacker is concerned, but requires user interaction: an administrator with an active OMSA session must load the attacker's link or page. Reachability depends on whether OMSA's web port is exposed to networks where admins browse.

What to do

Upgrade OMSA to 11.1.0.3 or later per DSA-2026-403 on every managed node, including the Windows patch package and the RHEL 8.10/9.4, SLES 15 and Ubuntu 22.04 managed-node builds. This is an agent package update and service restart, not a firmware flash or reboot. Until then, keep the OMSA web interface off general-purpose networks and avoid browsing elsewhere from an authenticated OMSA session.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.