GPU VulnDB

Database/Control plane, storage & DevOps

Dell OpenManage Server Administrator (authorization checks): A second, distinct flaw in the same OMSA versions

CVSS 6.5CVE-2026-81439Control plane, storage & DevOpscurated

Impact

A second, distinct flaw in the same OMSA versions: authorization is checked incorrectly, so a user who already holds a low-privilege account on the management service can bypass a protection mechanism and affect integrity (CVSS I:H). OMSA can drive hardware and firmware settings on the node it runs on, so an integrity bypass on a GPU node is a path to changing hardware configuration from an account that was not supposed to be able to. This is tracked separately from CVE-2026-81438 under the same DSA because the mechanism and the privilege requirement differ; the advisory does not detail which operations become reachable.

Who can reach it

A remote user with a low-privileged OMSA account on an affected node. Authentication required (PR:L).

What to do

Upgrade OMSA Managed Node to 11.1.0.3 or later per DSA-2026-403 - the same package upgrade that fixes CVE-2026-81438, so one maintenance action covers both. Agent services restart with the package; no reboot is specified. Meanwhile, review who holds low-privilege OMSA accounts and keep the service off routable networks.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.