GPU VulnDB

Database/Firmware, BMC & network fabric

Dell OMSA: improper privilege management lets a low-privileged remote user tamper with the node

CVSS 8.1CVE-2026-81442Firmware, BMC & network fabriccurated

Impact

A user who already holds a low-privileged OMSA account can act beyond that role, which Dell describes as information tampering and unauthorized access with high integrity and availability impact. On a fleet where OMSA credentials are handed to junior operators or to monitoring integrations, this collapses the distinction between read-only hardware monitoring and the ability to change hardware settings or take a node down. Recovery on a GPU node is expensive because the node has to be drained before it can be inspected or rebuilt.

Who can reach it

Network access to OMSA with any low-privileged OMSA account.

What to do

Upgrade OMSA to 11.1.0.3 or later on every managed node and restart the OMSA services. In the meantime review who holds non-admin OMSA accounts and whether service integrations need them at all.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.