GPU VulnDB

Database/Firmware, BMC & network fabric

Dell OMSA: high-privileged remote user escalates beyond their assigned OMSA role

CVSS 7.2CVE-2026-81445Firmware, BMC & network fabriccurated

Impact

An account already holding high OMSA privilege can escalate further, taking full confidentiality, integrity and availability of the node. The practical concern is that OMSA's administrative role stops being a boundary at all: an operator scoped to hardware administration on one server crosses into full host control. This is the lowest-urgency item in DSA-2026-403 for operators who tightly control admin accounts, and it ships in the same package as the rest.

Who can reach it

Network access to OMSA with a high-privileged (administrative) OMSA account.

What to do

Upgrade OMSA to 11.1.0.3 or later on all managed nodes and restart the OMSA services, alongside the other DSA-2026-403 fixes.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.