GPU VulnDB

Database/Firmware, BMC & network fabric

Dell OMSA: unauthenticated SSRF turns the management agent into a proxy into the management VLAN

CVSS 7.4CVE-2026-81446Firmware, BMC & network fabriccurated

Impact

OMSA can be made to issue attacker-chosen requests, and Dell rates this with a scope change and high confidentiality impact, meaning the responses reach systems beyond OMSA itself. In a datacenter that is the whole point of the bug: the OMSA agent sits on the management network alongside iDRACs, switch management interfaces and fabric managers that are not reachable from where the attacker is. The CVSS vector marks user interaction as required, so some operator action is part of the path. CVE-2026-81443 is a separate SSRF that requires a low-privileged account.

Who can reach it

Network access to the OMSA service, no authentication, but user interaction is required per Dell's CVSS vector.

What to do

Upgrade OMSA to 11.1.0.3 or later on all managed nodes and restart the OMSA services. Egress filtering from OMSA hosts toward BMC and switch management addresses limits the blast radius but Dell publishes no supported workaround.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.