GPU VulnDB

Database/Firmware, BMC & network fabric

Dell OMSA: hard-coded credentials give an unauthenticated remote attacker access

CVSS 7.3CVE-2026-81440Firmware, BMC & network fabriccurated

Impact

Credentials shipped in the product let an unauthenticated network attacker log in to the hardware management agent on any node running an affected OMSA version. Impact is rated low across confidentiality, integrity and availability, so this is a foothold in the management plane rather than immediate node takeover - but it is the same credential on every node, so it scales across the whole fleet without any additional work for the attacker. This is distinct from CVE-2026-81478, which is a hard-coded cryptographic key rather than a credential.

Who can reach it

Network access to the OMSA service. No authentication required.

What to do

Upgrade OMSA to 11.1.0.3 or later on all managed nodes and restart the OMSA services. Changing local account passwords does not remove credentials compiled into the shipped version.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.