Database/Control plane, storage & DevOps
Dell OpenManage Server Administrator (authorization checks): A second, distinct flaw in the same OMSA versions
Impact
A second, distinct flaw in the same OMSA versions: authorization is checked incorrectly, so a user who already holds a low-privilege account on the management service can bypass a protection mechanism and affect integrity (CVSS I:H). OMSA can drive hardware and firmware settings on the node it runs on, so an integrity bypass on a GPU node is a path to changing hardware configuration from an account that was not supposed to be able to. This is tracked separately from CVE-2026-81438 under the same DSA because the mechanism and the privilege requirement differ; the advisory does not detail which operations become reachable.
Who can reach it
A remote user with a low-privileged OMSA account on an affected node. Authentication required (PR:L).
What to do
Upgrade OMSA Managed Node to 11.1.0.3 or later per DSA-2026-403 - the same package upgrade that fixes CVE-2026-81438, so one maintenance action covers both. Agent services restart with the package; no reboot is specified. Meanwhile, review who holds low-privilege OMSA accounts and keep the service off routable networks.
References
Related entries
- Airflow Akeyless provider: path-shaped Variable key bypasses the team-scope guard on secret lookupCVE-2026-86465 · Apache Airflow Akeyless provider (secrets backend, team-scope guard)Medium
- Jenkins Bitbucket Push and Pull Request Plugin: webhook payload can redirect credentialed requestsCVE-2026-92139 · Jenkins Bitbucket Push and Pull Request Plugin (webhook-supplied URLs)Medium
- Airflow HashiCorp provider: path-shaped Variable key crosses team scope in the Vault secrets backendCVE-2026-97636 · Apache Airflow HashiCorp provider (Vault secrets backend, team-scoped variable lookup)Medium
- Ceph (Python bindings, IMAP4_SSL/SMTP_SSL TLS clients): Ceph's Python code constructs imaplib.IMAP4_SSL andNCVD-2024-010-ceph-python-bindings-imap4-ssl-s · Ceph (Python bindings, IMAP4_SSL/SMTP_SSL TLS clients)Medium
- rclone (serve s3): Path traversal in rclone's S3 gateway lets a caller read and overwrite files above the served root.NCVD-2026-042-rclone-serve-s3 · rclone (serve s3)Medium
- KubeEdge CloudHub (viaduct packer, pkg/viaduct/pkg/packer): ONE COMPROMISED EDGE NODE TAKES DOWN CLOUD-EDGENCVD-2026-053-kubeedge-cloudhub-viaduct-packer · KubeEdge CloudHub (viaduct packer, pkg/viaduct/pkg/packer)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.