GPU VulnDB

Database/Firmware, BMC & network fabric

Dell OMSA: authenticated path traversal lets a low-privileged user read files off the node

CVSS 6.5CVE-2026-81453Firmware, BMC & network fabriccurated

Impact

A holder of a low-privileged OMSA account can read files outside the intended directory on the managed node. That turns a monitoring-level account - the kind handed to NOC staff or to an integration - into arbitrary file read on a GPU host, where node credentials and cluster tokens live. Dell does not name the affected handler or the reachable paths.

Who can reach it

Network access to OMSA with any low-privileged OMSA account.

What to do

Upgrade OMSA to 11.1.0.3 or later on all managed nodes and restart the OMSA services. Review which accounts and integrations hold low-privileged OMSA access in the meantime.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.